CVE-2006-7094
EPSS 2.6%
Description
ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.
How to fix CVE-2006-7094
To remediate CVE-2006-7094, upgrade the affected package to a fixed version below.
- Debian/linux-ftpd—upgrade to 0.17-23 or later
Is CVE-2006-7094 being exploited?
Low — EPSS is 2.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.17-23