Incorrect Privilege Assignment The advisory has been revoked - it doesn't affect any version of package pureftpd  (opens in a new tab)


Threat Intelligence

EPSS
0.34% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Privilege Assignment vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-PUREFTPD-2371146
  • published26 Jan 2022
  • disclosed18 Apr 2011
  • creditUnknown

Introduced: 18 Apr 2011

CVE-2011-0988  (opens in a new tab)
CWE-266  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Incorrect Privilege Assignment pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.

Note:

This issue does not affect upstream pure-ftpd package, only as used by SUSE.

References