CVE-2011-0988
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
18/04/2011
Last modified:
11/04/2025
Description
pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.
Impact
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pureftpd:pure-ftpd:1.0.22:*:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:suse_linux:10:sp3:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:suse_linux:10:sp4:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:suse_linux:11:sp3:desktop:*:*:*:*:* | ||
| cpe:2.3:o:novell:suse_linux:11:sp4:desktop:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



