PT-2004-1017 · Lukemftp · Lukemftpd
Published
2004-08-19
·
Updated
2017-07-11
·
CVE-2004-0794
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
lukemftpd versions prior to 20040810
Description
The issue concerns multiple vulnerabilities in the lukemftpd package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, signal handler race conditions in lukemftpd allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
Recommendations
For versions prior to 20040810, update to a version 20040810 or later to resolve the issue. As a temporary workaround, consider restricting access to the lukemftpd service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lukemftpd