Back

MEDIUM

krb5-appl: ftpd incorrect group privilege dropping (MITKRB5-SA-2011-005)

Published Jul 11, 2011

Description

ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.

Affected products

Remediation

Red Hat statement

This issue was addressed in krb5-appl packages in Red Hat Enterprise Linux 6 via RHSA-2011:0920 and krb5 packages in Red Hat Enterprise Linux 5 via RHSA-2012:0306. This issue is not planned to be addressed in Red Hat Enterprise Linux 4, where this issue was rated as having low security impact.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 11, 2011
Updated Aug 6, 2024
Reserved Mar 29, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 5, 2011