Junglewise Threat Intelligence

CVE-1999-0083: Generic FTP file descriptor leak in getcwd

CVE-1999-0083 · Severity: medium · CVSS 5 · Published 1997-06-11

Technologies: Sgi Irix. Vendors: Sgi, Unknown.

Executive brief

A vulnerability exists in certain FTP services where the system fails to properly close file handles when determining the current working directory. This could allow a remote user to potentially gain unauthorized access to information about the server's file system structure. While it does not directly allow for file modification, it can be used as a stepping stone for further attacks or to exhaust system resources.

Technical details

The vulnerability is a file descriptor leak occurring within the getcwd() function call in various FTP server implementations. When the FTP service processes directory-related commands, it fails to properly close file descriptors associated with directory lookups. An attacker can exploit this over the network without authentication to leak information or potentially cause a resource exhaustion (denial of service) by consuming all available file descriptors. This is a classic resource management error (CWE-772/CWE-403) typical of early Unix-based network services.

Affected products

  • Unknown FTP Service

Timeline

  • 1997-06-11: disclosed: Initial publication date in NVD.

References

Related threats