Brian Ristuccia discovered that in ProFTPD, a powerful modular FTP/SFTP/FTPS server, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
https://security-tracker.debian.org/tracker/DSA-5827-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5827-1
Continue reading...

