PT-1997-1225 · Freebsd · Freebsd

Published

1997-04-07

·

Updated

2008-09-10

·

CVE-1999-1298

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeBSD versions 2.2.1 and earlier
Description The issue concerns the configuration of anonymous FTP by Sysinstall. When this configuration is set up, it creates an ftp user without a password and assigns /bin/date as the shell. This setup could potentially allow attackers to access certain system resources.
Recommendations For versions 2.2.1 and earlier, consider setting a strong password for the ftp user and changing the shell assignment to a more secure option to prevent unauthorized access. As a temporary workaround, restrict access to the ftp user account until a more permanent solution can be applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1298

Affected Products

Freebsd