CVE-2024-48651
Published Nov 29, 2024
·Updated
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
Affected Software
2 affected componentsFixes available
ProFTPD ProFTPD<1.3.8b
debian/proftpd-dfsg<=1.3.7a+dfsg-12+deb11u2
1.3.7a+dfsg-12+deb11u51.3.8+dfsg-4+deb12u41.3.8.c+dfsg-21.3.8.c+dfsg-4
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Feb 25, 2025
Data Sourced
via Launchpad·06:00 PM
Description
Mar 1, 2025
Data Sourced
via Ubuntu·06:00 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-48651?
CVE-2024-48651 has been classified with a high severity due to the potential for unauthorized access to GID 0.
2
How do I fix CVE-2024-48651?
To remediate CVE-2024-48651, upgrade ProFTPD to version 1.3.8b or later.
3
What are the affected versions for CVE-2024-48651?
CVE-2024-48651 affects ProFTPD versions before 1.3.8b.
4
What is the cause of CVE-2024-48651?
CVE-2024-48651 is caused by supplemental group inheritance that grants unintended access due to issues with mod_sql.
5
Is there a workaround for CVE-2024-48651?
As of now, the only effective solution for CVE-2024-48651 is to upgrade to the fixed version of ProFTPD.