CVE-2001-0456: High severity Debian Debian Linux vulnerability
postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0456?
CVE-2001-0456 is considered a high severity vulnerability due to the risk of privilege escalation.
How do I fix CVE-2001-0456?
To fix CVE-2001-0456, ensure that the ProFTPD installation script is properly configured to not run with root privileges when anonymous access is enabled.
What systems are affected by CVE-2001-0456?
CVE-2001-0456 affects Debian GNU/Linux version 2.2 specifically.
What are the implications of CVE-2001-0456?
The implications of CVE-2001-0456 include the potential for unauthorized users to gain elevated privileges on the server.
Is there a patch available for CVE-2001-0456?
Yes, a patch is available that addresses the privilege escalation issue in CVE-2001-0456.