Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24791
HistoryApr 10, 2020 - 1:05 a.m.

Privilege Escalation

2020-04-1001:05:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.004 Low

EPSS

Percentile

72.0%

krb5-appl package is vulnerable to privilege escalation. It was found that gssftp, a Kerberos-aware FTP server, did not properly drop privileges. A remote FTP user could use this flaw to gain unauthorized read or write access to files that are owned by the root group.

References