Executive brief
The wu-ftpd file transfer service contains a critical flaw that allows users to log in using any username and password combination. This service is typically used to allow users to upload and download files from a server. An exploit of this vulnerability would allow unauthorized individuals to gain access to the system, potentially leading to the theft of sensitive data or the disruption of operations.
Technical details
A vulnerability in the wu-ftpd FTP daemon's authentication mechanism allows for an authentication bypass where any username and password combination is accepted. The root cause is an improper validation of credentials during the login process. While the CVSS 2.0 vector suggests a local attack vector, this typically manifests as a remote authentication bypass in the context of an FTP service. An attacker can gain unauthorized access to the file system with the privileges of the FTP service, allowing for unauthorized reading, writing, or deletion of files. This is a legacy vulnerability originally reported in 1997.
Affected products
- Washington University wu-ftpd
Timeline
- 1997-07-01: disclosed: Initial publication date in NVD.