FlawAtlas
Search the atlas
UBUNTU-CVE-2024-48651 High

UBUNTU-CVE-2024-48651

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

Exploit probability Not scored
Published November 29, 2024
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:20.04:LTS proftpd-dfsg

3 explicit affected versions

Ubuntu:22.04:LTS proftpd-dfsg

2 explicit affected versions

Ubuntu:24.04:LTS proftpd-dfsg

6 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2024-48651

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

View original source

05 / REFERENCES

Further evidence