PT-1999-1730 · Proftpd · Proftpd

Published

1999-11-19

·

Updated

2008-09-05

·

CVE-1999-1475

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ProFTPd version 1.2
Description: The issue allows local users to obtain user passwords and gain privileges by reading the wtmp log file, which contains recorded user passwords when ProFTPd is compiled with the mod sqlpw module. This can be achieved, for example, via the last command.
Recommendations: For ProFTPd version 1.2, consider disabling the mod sqlpw module to prevent passwords from being recorded in the wtmp log file until a more permanent solution is available. Restrict access to the wtmp log file to minimize the risk of password exposure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1475

Affected Products

Proftpd