wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/7169 | vdb entry |
http://marc.info/?l=bugtraq&m=87602167420408&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=87602167420401&w=2 | mailing list |