CVE-2006-7094

Source
https://cve.org/CVERecord?id=CVE-2006-7094
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2006-7094.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2006-7094
Downstream
Published
2007-03-02T21:18:00Z
Modified
2026-04-10T03:38:39.494034Z
Summary
[none]
Details

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.

References

Affected packages