Upstream information

CVE-2024-48651 at MITRE

Description

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v3 Scores
  CNA (CISA-ADP)
Base Score 7.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1233997 [IN_PROGRESS]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP6
  • proftpd >= 1.3.8c-bp156.2.3.1
  • proftpd-devel >= 1.3.8c-bp156.2.3.1
  • proftpd-doc >= 1.3.8c-bp156.2.3.1
  • proftpd-lang >= 1.3.8c-bp156.2.3.1
  • proftpd-ldap >= 1.3.8c-bp156.2.3.1
  • proftpd-mysql >= 1.3.8c-bp156.2.3.1
  • proftpd-pgsql >= 1.3.8c-bp156.2.3.1
  • proftpd-radius >= 1.3.8c-bp156.2.3.1
  • proftpd-sqlite >= 1.3.8c-bp156.2.3.1
Patchnames:
openSUSE-2025-15
openSUSE Leap 15.6
  • proftpd >= 1.3.8c-bp156.2.3.1
  • proftpd-devel >= 1.3.8c-bp156.2.3.1
  • proftpd-doc >= 1.3.8c-bp156.2.3.1
  • proftpd-lang >= 1.3.8c-bp156.2.3.1
  • proftpd-ldap >= 1.3.8c-bp156.2.3.1
  • proftpd-mysql >= 1.3.8c-bp156.2.3.1
  • proftpd-pgsql >= 1.3.8c-bp156.2.3.1
  • proftpd-radius >= 1.3.8c-bp156.2.3.1
  • proftpd-sqlite >= 1.3.8c-bp156.2.3.1
Patchnames:
openSUSE-2025-15
openSUSE Tumbleweed
  • proftpd >= 1.3.8c-1.1
  • proftpd-devel >= 1.3.8c-1.1
  • proftpd-doc >= 1.3.8c-1.1
  • proftpd-lang >= 1.3.8c-1.1
  • proftpd-ldap >= 1.3.8c-1.1
  • proftpd-mysql >= 1.3.8c-1.1
  • proftpd-pgsql >= 1.3.8c-1.1
  • proftpd-radius >= 1.3.8c-1.1
  • proftpd-sqlite >= 1.3.8c-1.1
Patchnames:
openSUSE-Tumbleweed-2025-14636


SUSE Timeline for this CVE

CVE page created: Fri Nov 29 08:00:17 2024
CVE page last modified: Fri Jan 31 17:07:45 2025