pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.
2011-04-18T17:55:01.030
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pureftpd | pure-ftpd | 1.0.22 | Yes |
Operating System | novell | suse_linux | 10 | Yes |
Operating System | novell | suse_linux | 10 | Yes |
Operating System | novell | suse_linux | 11 | Yes |
Operating System | novell | suse_linux | 11 | Yes |