ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks
Published Apr 4, 2017
5.5
MEDIUMCVSS 3.0
EPSS 0.42%
Description
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
AV:L/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.42% (0.00419) | 33.92th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.42% (0.00419) | 35.90th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.10% (0.01104) | 54.09th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.10% (0.01104) | 28.85th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.00% (0.00999) | 27.22th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.00% (0.00999) | 0.00th | v1 |
References (8)
- http://bugs.proftpd.org/show_bug.cgi?id=4295 x_refsource_CONFIRMIssue TrackingPatch
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00022.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/97409 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://github.com/proftpd/proftpd/commit/ecff21e0d0e84f35c299ef91d7fda088e516d4ed x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/proftpd/proftpd/commit/f59593e6ff730b832dbe8754916cb5c821db579f x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/proftpd/proftpd/pull/444/commits/349addc3be4fcdad9bd4ec01ad1ccd916c898ed8 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://bugs.proftpd.org/show_bug.cgi?id=4295 | x_refsource_CONFIRMIssue TrackingPatch | |
| http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00004.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00022.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.html | vendor-advisoryx_refsource_SUSE | |
| http://www.securityfocus.com/bid/97409 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://github.com/proftpd/proftpd/commit/ecff21e0d0e84f35c299ef91d7fda088e516d4ed | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://github.com/proftpd/proftpd/commit/f59593e6ff730b832dbe8754916cb5c821db579f | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://github.com/proftpd/proftpd/pull/444/commits/349addc3be4fcdad9bd4ec01ad1ccd916c898ed8 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory |
Change history (0)
No recorded changes yet.