Junglewise Threat Intelligence

CVE-1999-0035: ftpd race condition in signal handling routine

CVE-1999-0035 · Severity: medium · CVSS 5.4 · Published 1997-05-29

Technologies: Sgi Irix. Vendors: Sgi, Unknown.

Executive brief

A vulnerability exists in the file transfer service (ftpd) that could allow an authenticated user to read or write to unauthorized files on the server. This occurs due to a timing flaw in how the service handles internal signals, potentially leading to the exposure of sensitive data or the modification of system files. Organizations using legacy FTP services should ensure they are patched or migrated to secure alternatives.

Technical details

A race condition (CWE-364) exists within the signal handling routine of the ftpd daemon. By exploiting a timing window during signal processing, a remote authenticated attacker can bypass intended file system permissions. This flaw allows for the unauthorized reading or writing of arbitrary files with the privileges of the FTP process. The vulnerability is reachable over the network but typically requires valid user credentials to interact with the service.

Affected products

  • unknown ftpd

Timeline

  • 1997-05-29: disclosed: Initial NVD publication date

References

Related threats