CVE-2012-6095 - CERT CVE
ID CVE-2012-6095
Sažetak ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
Reference
CVSS
Base: 1.2
Impact: 2.9
Exploitability:1.9
Pristup
VektorSloženostAutentikacija
LOCAL HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL NONE
CVSS vektor AV:L/AC:H/Au:N/C:N/I:P/A:N
Zadnje važnije ažuriranje 25-01-2013 - 05:00
Objavljeno 24-01-2013 - 21:55