Vulnerability in ftpd from FreeBSD that allowed root access when using ftpchroot
A critical vulnerability (CVE-2020-7468) has been identified in the ftpd server included in FreeBSD, which allows users restricted to their home directory through the ftpchroot option to gain full root access to the system. The issue arises from a combination of an error in the implementation of the user isolation mechanism using the chroot call (non-fatal errors were reported during failures in changing uid or performing chroot and chdir, not […]
