ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://proftpd.org/docs/NEWS-1.3.5rc1 | |
http://www.openwall.com/lists/oss-security/2013/01/07/3 | mailing list |
http://bugs.proftpd.org/show_bug.cgi?id=3841 | |
http://secunia.com/advisories/51823 | third party advisory vendor advisory |
http://www.debian.org/security/2013/dsa-2606 | vendor advisory |