PT-1997-1229 · Washington University · Wu-Ftpd
Published
1997-07-04
·
Updated
2017-10-10
·
CVE-1999-1326
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
wu-ftpd version 2.4
Description
The issue arises from the wu-ftpd 2.4 FTP server's failure to properly drop privileges when an ABOR command is executed during a file transfer. This leads to incorrect signal handling, potentially allowing local and possibly remote attackers to read arbitrary files.
Recommendations
For wu-ftpd version 2.4, consider restricting access to the ABOR command until a fix is available, or apply configuration changes that mitigate the risk of privilege escalation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wu-Ftpd