CVE-2012-6095: ProFTPD

Low severity, CVSS 1.2. EPSS: 0.7% chance of exploitation in the next 30 days.

ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.

Affected products

  • ProFTPD ProFTPD: up to and including 1.3.4; version 1.2.0 only; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only; version 1.2.4 only; …

Published 2013-01-24. Last modified 2026-06-16.