DEBIAN-CVE-2006-7094

Source
https://security-tracker.debian.org/tracker/CVE-2006-7094
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-7094.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2006-7094
Upstream
Published
2007-03-02T21:18:00Z
Modified
2026-09-12T06:47:26Z
Summary
[none]
Details

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.

References

Affected packages

Debian:12 / linux-ftpd

Package

Name
linux-ftpd
Purl
pkg:deb/debian/linux-ftpd?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.17-23

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-7094.json"