Vulnerability in ftpd from FreeBSD that allowed root access when using ftpchroot

In the ftpd server included with FreeBSD identified a critical vulnerability (CVE-2020-7468) that allows users limited to their home directory using the ftpchroot option to gain full root access to the system.

The issue is caused by a combination of an error in the implementation of the user isolation mechanism via the chroot call (non-fatal errors were returned during uid changes or executing chroot and chdir that did not terminate the session) and granting authenticated FTP users sufficient rights to bypass the root path restriction in the filesystem. The vulnerability does not manifest when accessing the FTP server in anonymous mode or when a user logs in without ftpchroot. The issue has been resolved in updates 12.1-RELEASE-p10, 11.4-RELEASE-p4, and 11.3-RELEASE-p14.

Additionally, it is worth noting the resolution of three more vulnerabilities in 12.1-RELEASE-p10, 11.4-RELEASE-p4, and 11.3-RELEASE-p14:

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster