Executive brief
A vulnerability exists in the wu-ftpd software, a common tool used for transferring files between computers. An attacker can cause the file transfer service to crash or behave unexpectedly by sending a specific command after logging in. This can disrupt file transfer operations and potentially impact the availability of the server for legitimate users.
Technical details
The wu-ftpd daemon contains a vulnerability that leads to a core dump when processing the PASV (passive mode) command. An attacker must first authenticate with a valid username and password before issuing a 'QUOTE PASV' command to trigger the flaw. This issue is categorized as a denial-of-service or unexpected termination vulnerability within the FTP service handling. The vulnerability was first identified in 1996 and affects early versions of the Washington University FTP daemon.
Affected products
- Washington University wu-ftpd
Timeline
- 1996-10-16: disclosed: NVD Published Date