First published: Fri Nov 29 2024(Updated: )
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ProFTPD | <1.3.8b | |
debian/proftpd-dfsg | <=1.3.7a+dfsg-12+deb11u2 | 1.3.7a+dfsg-12+deb11u5 1.3.8+dfsg-4+deb12u4 1.3.8.c+dfsg-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48651 has been classified with a high severity due to the potential for unauthorized access to GID 0.
To remediate CVE-2024-48651, upgrade ProFTPD to version 1.3.8b or later.
CVE-2024-48651 affects ProFTPD versions before 1.3.8b.
CVE-2024-48651 is caused by supplemental group inheritance that grants unintended access due to issues with mod_sql.
As of now, the only effective solution for CVE-2024-48651 is to upgrade to the fixed version of ProFTPD.