CVE-2020-8634: High severity Wftpserver Wing Ftp Server Linux vulnerability
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8634?
CVE-2020-8634 is a vulnerability in Wing FTP Server v6.2.3 for Linux, macOS, and Solaris that sets insecure permissions on files modified within the HTTP file management interface.
What are the affected software versions of CVE-2020-8634?
The affected software version is Wing FTP Server v6.2.3 for Linux, macOS, and Solaris.
What are the consequences of CVE-2020-8634?
Files modified within the HTTP file management interface may be saved with world-readable and world-writable permissions, potentially allowing low-privilege users to access sensitive system files.
What is the severity of CVE-2020-8634?
CVE-2020-8634 has a severity score of 7.8 (high).
How can I fix CVE-2020-8634?
The vendor should release a patch or an update to Wing FTP Server to address the insecure permissions issue.