Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53963
Category:Slackware Local Security Checks
Title:Slackware: Security Advisory (SSA:2003-259-03)
Summary:The remote host is missing an update for the 'WU-FTPD' package(s) announced via the SSA:2003-259-03 advisory.
Description:Summary:
The remote host is missing an update for the 'WU-FTPD' package(s) announced via the SSA:2003-259-03 advisory.

Vulnerability Insight:
Upgraded WU-FTPD packages are available for Slackware 9.0 and
- -current. These fix a problem where an attacker could use a
specially crafted filename in conjunction with WU-FTPD's
conversion feature (mostly used to compress files, or produce tar
archives) to execute arbitrary commands on the server.

In addition, a MAIL_ADMIN which has been found to be insecure has
been disabled.

We do not recommend deploying WU-FTPD in situations where security
is required.


Here are the details from the Slackware 9.0 ChangeLog:
+--------------------------+
Tue Sep 23 14:43:10 PDT 2003
pasture/dontuse/wu-ftpd/wu-ftpd-2.6.2-i486-3.tgz: Fixed a security problem in
/etc/ftpconversions (CVE-1999-0997). There's also another hole in wu-ftpd
which may be triggered if the MAIL_ADMIN feature (notifies the admin of
anonymous uploads) is used, so MAIL_ADMIN has been disabled in this build.
Also note that we've moved this from /pasture to /pasture/dontuse, which
should tell you something.
(* Security fix *)
+--------------------------+

Affected Software/OS:
'WU-FTPD' package(s) on Slackware 9.0, Slackware current.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-1999-0997
Bugtraq: 19991220 Security vulnerability in certain wu-ftpd (and derivitives) configurations (fwd) (Google Search)
Debian Security Information: DSA-377 (Google Search)
http://www.debian.org/security/2003/dsa-377
XForce ISS Database: wuftp-ftp-conversion
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.