Directory Traversal (Chroot Escape) vulnerability in uftpd
Vulnerability Description
In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has been fixed in version 2.11
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5221
Credits & Attribution
No credits recorded in the NVD database.
References
More from troglobit
View All →Affected Vendor
troglobit
View all reports →