PT-1997-1225 · Freebsd · Freebsd
Published
1997-04-07
·
Updated
2008-09-10
·
CVE-1999-1298
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 2.2.1 and earlier
Description
The issue concerns the configuration of anonymous FTP by Sysinstall. When this configuration is set up, it creates an ftp user without a password and assigns /bin/date as the shell. This setup could potentially allow attackers to access certain system resources.
Recommendations
For versions 2.2.1 and earlier, consider setting a strong password for the ftp user and changing the shell assignment to a more secure option to prevent unauthorized access. As a temporary workaround, restrict access to the ftp user account until a more permanent solution can be applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd