Vulnerabilities > CVE-1999-0368

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
washington-university
proftpd-project
sco
slackware
redhat
debian
caldera
critical
nessus
exploit available

Summary

Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

Exploit-Db

  • descriptionwu-ftpd 2.4.2,SCO Open Server 5.0.5,ProFTPD 1.2 pre1 realpath Vulnerability (1). CVE-1999-0368. Remote exploit for linux platform
    idEDB-ID:19086
    last seen2016-02-02
    modified1999-02-09
    published1999-02-09
    reportersmiler and cossack
    sourcehttps://www.exploit-db.com/download/19086/
    titlewu-ftpd 2.4.2 & SCO Open Server <= 5.0.5 & ProFTPD 1.2 pre1 - realpath Vulnerability 1
  • descriptionwu-ftpd 2.4.2,SCO Open Server 5.0.5,ProFTPD 1.2 pre1 realpath Vulnerability (2). CVE-1999-0368. Remote exploit for linux platform
    idEDB-ID:19087
    last seen2016-02-02
    modified1999-02-09
    published1999-02-09
    reporterjamez and c0nd0r
    sourcehttps://www.exploit-db.com/download/19087/
    titlewu-ftpd 2.4.2 & SCO Open Server <= 5.0.5 & ProFTPD 1.2 pre1 - realpath Vulnerability 2

Nessus

  • NASL familyFTP
    NASL idPROFTPD_PRE10.NASL
    descriptionThe remote ProFTPd server is running a 1.2.0preN version. All the 1.2.0preN versions contain several security flaws that allow an attacker to execute arbitrary code on this host.
    last seen2020-06-01
    modified2020-06-02
    plugin id10464
    published2000-07-15
    reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/10464
    titleProFTPD Multiple Remote Overflows (palmetto)
  • NASL familyFTP
    NASL idWU_FTPD_OVERFLOW.NASL
    descriptionIt was possible to make the remote FTP server crash by creating a huge directory structure. This is usually called the
    last seen2020-06-01
    modified2020-06-02
    plugin id10318
    published1999-08-31
    reporterThis script is Copyright (C) 1999-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/10318
    titleWU-FTPD Multiple Vulnerabilities (OF, Priv Esc)