First published: Tue Nov 21 2006(Updated: )
ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these calls fail in cases such as PAM failures or resource limits, a different vulnerability than CVE-2006-5778.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netkit | =0.17 | |
=0.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6008 is classified as a high severity vulnerability due to the potential for privilege escalation.
To fix CVE-2006-6008, update to a version of Linux Netkit that has addressed this vulnerability.
CVE-2006-6008 affects remote authenticated users of Linux Netkit ftpd version 0.17 and possibly other vulnerable versions.
Exploitation of CVE-2006-6008 could allow remote authenticated users to gain elevated privileges on the system.
There are no known workarounds for CVE-2006-6008, and it is recommended to apply available patches.