ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.Referenceshttp://proftpd.org/docs/NEWS-1.3.5rc1http://www.openwall.com/lists/oss-security/2013/01/07/3http://bugs.proftpd.org/show_bug.cgi?id=3841http://secunia.com/advisories/51823http://www.debian.org/security/2013/dsa-2606