关键漏洞信息 CVE ID: CVE-2004-0346 CVSS v2 Base Score: 7 - Access Vector: Local - Access Complexity: Low - Authentication: Not Required - Confidentiality Impact: Complete - Integrity Impact: Complete - Availability Impact: Complete Description: A vulnerability has been found in ProFTPD versions prior to 1.2.9rc3 which allows attackers to execute arbitrary code on the system with the privileges of ProFTPD. Consequences: Gain Access Affected Products - ProFTPD: 1.2.7, 1.2.8, 1.2.9 rc1, 1.2.9 rc2 Dependent Products - Turbolinux: 7 Server, 7 Workstation, 8 Server, 8 Workstation Remedy: Upgrade to the latest version of ProFTPD (1.2.9rc3 or later), available from the ProFTPD Web site. References: BID-9782 CVE-2004-0346 ProFTPD Web site OSVDB ID: 4134