Junglewise Threat Intelligence

CVE-1999-0081: Washington University wu-ftpd file overwrite via rnfr command

CVE-1999-0081 · Severity: medium · CVSS 5 · Published 1997-01-11

Technologies: Washington University Wu-Ftpd. Vendors: Washington University.

Executive brief

A vulnerability in the wu-ftpd file transfer service allows remote users to overwrite existing files on the server. This could lead to the corruption of important data or the replacement of legitimate files with malicious content. The issue stems from how the service handles file renaming commands, potentially impacting the integrity of the hosted file system.

Technical details

The wu-ftpd service contains a vulnerability in its handling of the FTP 'RNFR' (Rename From) command. An attacker can leverage this flaw to overwrite files on the target system, potentially bypassing intended file system protections. The vulnerability is exploitable over the network without requiring specific authentication beyond what is needed to access the FTP service. This issue is classified as an improper input validation or logic flaw within the file renaming routine. Users should update to a patched version of wu-ftpd or migrate to a more secure FTP daemon.

Affected products

  • Washington University wu-ftpd

Timeline

  • 1997-01-11: disclosed: Initial publication date in NVD

References

Related threats