VULNERABILITY INTELLIGENCE

CVE-2012-6095

CVSS score1.2 LOW
EPSS probability0.69%
CISA KEVNot currently listed
Published2013-01-24
Last modified2026-06-16

Description

ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.