AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-7094

HIGH · CVSS 8.5 EPSS 2.56%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-03-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-7094
Severity
HIGH
CVSS
8.5
EPSS
2.56%
Linux Debian

Original NVD Description

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.