PT-2004-1017 · Lukemftp · Lukemftpd

Published

2004-08-19

·

Updated

2017-07-11

·

CVE-2004-0794

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions lukemftpd versions prior to 20040810
Description The issue concerns multiple vulnerabilities in the lukemftpd package, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, signal handler race conditions in lukemftpd allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
Recommendations For versions prior to 20040810, update to a version 20040810 or later to resolve the issue. As a temporary workaround, consider restricting access to the lukemftpd service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02950
CVE-2004-0794
DSA-551-1

Affected Products

Lukemftpd