CVE-2020-7468 Information
Jun 07, 2022
cve
Description
In FreeBSD 12.2-STABLE before r365772 11.4-STABLE before r365773 12.1-RELEASE before p10 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a ftpd(8) bug in the implementation of the file system sandbox combined with capabilities available to an authenticated FTP user can be used to escape the file system restriction configured in ftpchroot(5). Moreover the bug allows a malicious client to gain root privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:30.ftpd.asc
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: