CVE-2017-7418
published 2017-04-04CVE-2017-7418: ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks…
PriorityP425medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.42%
34.0th percentile
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | proftpd-dfsg | < proftpd-dfsg 1.3.5b-4 (bookworm) | proftpd-dfsg 1.3.5b-4 (bookworm) |
| proftpd | proftpd | <= 1.3.5 | — |
| proftpd | proftpd | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mq6p-g6qc-37c9: ProFTPD before 1
ghsa_unreviewed·2022-05-14
CVE-2017-7418 [MEDIUM] CWE-59 GHSA-mq6p-g6qc-37c9: ProFTPD before 1
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
OSV
CVE-2017-7418: ProFTPD before 1
osv·2017-04-04·CVSS 5.5
CVE-2017-7418 [MEDIUM] CVE-2017-7418: ProFTPD before 1
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
Debian
CVE-2017-7418: proftpd-dfsg - ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home direct...
vendor_debian·2017·CVSS 5.5
CVE-2017-7418 [MEDIUM] CVE-2017-7418: proftpd-dfsg - ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home direct...
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
Scope: local
bookworm: resolved (fixed in 1.3.5b-4)
bullseye: resolved (fixed in 1.3.5b-4)
forky: resolved (fixed in 1.3.5b-4)
sid: resolved (fixed in 1.3.5b-4)
trixie: resolved (fixed in 1.3.5b-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass [fedora-all]
bugzilla·2017-04-06·CVSS 5.5
CVE-2017-7418 [MEDIUM] CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass [fedora-all]
CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass
bugzilla·2017-04-06·CVSS 5.5
CVE-2017-7418 [MEDIUM] CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass
CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass
ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.
Upstream patch (1.3.5 branch):
https://github.com/proftpd/proftpd/commit/ecff21e0d0e84f35c299ef91d7fda088e516d4ed
Upstream bug:
http://bugs.proftpd.org/show_bug.cgi?id=4295
Bugzilla
CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass [epel-all]
bugzilla·2017-04-06·CVSS 5.5
CVE-2017-7418 [MEDIUM] CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass [epel-all]
CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
http://bugs.proftpd.org/show_bug.cgi?id=4295http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.htmlhttp://www.securityfocus.com/bid/97409https://github.com/proftpd/proftpd/commit/ecff21e0d0e84f35c299ef91d7fda088e516d4edhttps://github.com/proftpd/proftpd/commit/f59593e6ff730b832dbe8754916cb5c821db579fhttps://github.com/proftpd/proftpd/pull/444/commits/349addc3be4fcdad9bd4ec01ad1ccd916c898ed8http://bugs.proftpd.org/show_bug.cgi?id=4295http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.htmlhttp://www.securityfocus.com/bid/97409https://github.com/proftpd/proftpd/commit/ecff21e0d0e84f35c299ef91d7fda088e516d4edhttps://github.com/proftpd/proftpd/commit/f59593e6ff730b832dbe8754916cb5c821db579fhttps://github.com/proftpd/proftpd/pull/444/commits/349addc3be4fcdad9bd4ec01ad1ccd916c898ed8
2017-04-04
Published