PT-2004-1330 · Washington University · Wu-Ftpd
Published
2004-04-15
·
Updated
2018-05-03
·
CVE-2004-0148
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
wu-ftpd versions 2.6.2 and earlier
Description
The issue allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory. As a result, wu-ftpd uses the root directory instead, potentially leading to unauthorized access.
Recommendations
For wu-ftpd versions 2.6.2 and earlier, consider disabling the restricted-gid option as a temporary workaround to prevent exploitation. Restrict access to sensitive directories to minimize the risk of unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wu-Ftpd