{"id":"CVE-2012-6095","details":"ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.","modified":"2026-04-10T03:42:33.903048Z","published":"2013-01-24T21:55:01Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/51823"},{"type":"ADVISORY","url":"http://www.debian.org/security/2013/dsa-2606"},{"type":"WEB","url":"http://bugs.proftpd.org/show_bug.cgi?id=3841"},{"type":"WEB","url":"http://proftpd.org/docs/NEWS-1.3.5rc1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/01/07/3"}],"schema_version":"1.7.5"}