Junglewise Threat Intelligence

CVE-1999-0075: Washington University wu-ftpd core dump via PASV command

CVE-1999-0075 · Severity: medium · CVSS 5 · Published 1996-10-16

Technologies: Washington University Wu-Ftpd. Vendors: Washington University.

Executive brief

A vulnerability exists in the wu-ftpd software, a common tool used for transferring files between computers. An attacker can cause the file transfer service to crash or behave unexpectedly by sending a specific command after logging in. This can disrupt file transfer operations and potentially impact the availability of the server for legitimate users.

Technical details

The wu-ftpd daemon contains a vulnerability that leads to a core dump when processing the PASV (passive mode) command. An attacker must first authenticate with a valid username and password before issuing a 'QUOTE PASV' command to trigger the flaw. This issue is categorized as a denial-of-service or unexpected termination vulnerability within the FTP service handling. The vulnerability was first identified in 1996 and affects early versions of the Washington University FTP daemon.

Affected products

  • Washington University wu-ftpd

Timeline

  • 1996-10-16: disclosed: NVD Published Date

References

Related threats