This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.
The remote FTP server is affected by an arbitrary file overwrite
The remote host is using ProFTPD, a free FTP server for Unix and Linux.
According to its banner, the version of ProFTPD installed on the remote
host earlier than 1.3.4c. As such, it is potentially affected by a race
condition error that does not securely create temporary files related to
symlinks and newly created directories. A local, attacker could
leverage this issue to overwrite arbitrary files and elevate privileges.
Note that Nessus did not actually test for the flaw but has instead
relied on the version in ProFTPD's banner.
See also :
Upgrade to 1.3.4c / 1.3.5rc1 or apply the patch from the vendor.
Risk factor :
Low / CVSS Base Score : 1.2
CVSS Temporal Score : 0.9
Public Exploit Available : false
Nessus Plugin ID: 66970 ()
Bugtraq ID: 57172
CVE ID: CVE-2012-6095
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.