Executive brief
A critical vulnerability in the standard FTP server software allows remote attackers to gain full administrative control over the system. By sending a specific command, an unauthorized user can bypass security restrictions and access the root directory. This could lead to the complete theft of data, system destruction, or the installation of malicious software.
Technical details
A vulnerability exists in certain implementations of the FTP daemon (ftpd) related to the handling of the 'Change Working Directory' (CWD) command. When a user provides the '~root' argument to the CWD command, the daemon incorrectly resolves the path, granting the user access to the root user's home directory or elevated privileges. This is a remote, unauthenticated attack vector that results in a complete compromise of confidentiality, integrity, and availability. The flaw stems from improper validation of tilde-expansion in the FTP service.
Affected products
- unknown ftpd
Timeline
- 1988-11-11: disclosed: Initial publication date recorded in NVD.