CVE-2024-48651: High severity proftpd vulnerability
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from modsql.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48651?
CVE-2024-48651 has been classified with a high severity due to the potential for unauthorized access to GID 0.
How do I fix CVE-2024-48651?
To remediate CVE-2024-48651, upgrade ProFTPD to version 1.3.8b or later.
What are the affected versions for CVE-2024-48651?
CVE-2024-48651 affects ProFTPD versions before 1.3.8b.
What is the cause of CVE-2024-48651?
CVE-2024-48651 is caused by supplemental group inheritance that grants unintended access due to issues with mod_sql.
Is there a workaround for CVE-2024-48651?
As of now, the only effective solution for CVE-2024-48651 is to upgrade to the fixed version of ProFTPD.