
CVE-2006-5778
https://notcve.org/view.php?id=CVE-2006-5778
07 Nov 2006 — ftpd in linux-ftpd 0.17, and possibly other versions, performs a chdir before setting the UID, which allows local users to bypass intended access restrictions by redirecting their home directory to a restricted directory. ftpd en linux-ftpd 0.17, y posiblemente otras versiones, efectúa un chdir antes de establecer el UID, lo cual permite a usuarios locales evitar las restricciones de acceso previstas redireccionando su directorio home a un directorio restringido. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=384454 •

CVE-2005-3524 – linux-ftpd-ssl 0.17 - 'MKD'/'CWD' Remote Code Execution
https://notcve.org/view.php?id=CVE-2005-3524
07 Nov 2005 — Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command. • https://www.exploit-db.com/exploits/1295 •