PT-1999-1730 · Proftpd · Proftpd

Publicado

1999-11-19

·

Atualizado

2008-09-05

·

CVE-1999-1475

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ProFTPd version 1.2
Description: The issue allows local users to obtain user passwords and gain privileges by reading the wtmp log file, which contains recorded user passwords when ProFTPd is compiled with the mod sqlpw module. This can be achieved, for example, via the last command.
Recommendations: For ProFTPd version 1.2, consider disabling the mod sqlpw module to prevent passwords from being recorded in the wtmp log file until a more permanent solution is available. Restrict access to the wtmp log file to minimize the risk of password exposure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1475

Produtos afetados

Proftpd