Vulnerabilities > CVE-1999-0075 - Unspecified vulnerability in Washington University Wu-Ftpd

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
washington-university
nessus

Summary

PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.

Vulnerable Configurations

Part Description Count
Application
Washington_University
1

Nessus

NASL familyFTP
NASL idFTP_PASV_ON_CONNECT.NASL
descriptionThe remote FTP server fails to handle QUOTE PASV requests for logged in users. An attacker can send a specially crafted requests to cause the service to die and dump core. The core file contains the usernames and passwords of all users.
last seen2020-06-01
modified2020-06-02
plugin id10086
published1999-06-22
reporterThis script is Copyright (C) 1999-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10086
titleWU-FTPD QUOTE PASV Forced Core Dump Information Disclosure