Junglewise Threat Intelligence

CVE-1999-0156: Washington University wu-ftpd authentication bypass

CVE-1999-0156 · Severity: medium · CVSS 4.6 · Published 1997-07-01

Technologies: Washington University Wu-Ftpd. Vendors: Washington University.

Executive brief

The wu-ftpd file transfer service contains a critical flaw that allows users to log in using any username and password combination. This service is typically used to allow users to upload and download files from a server. An exploit of this vulnerability would allow unauthorized individuals to gain access to the system, potentially leading to the theft of sensitive data or the disruption of operations.

Technical details

A vulnerability in the wu-ftpd FTP daemon's authentication mechanism allows for an authentication bypass where any username and password combination is accepted. The root cause is an improper validation of credentials during the login process. While the CVSS 2.0 vector suggests a local attack vector, this typically manifests as a remote authentication bypass in the context of an FTP service. An attacker can gain unauthorized access to the file system with the privileges of the FTP service, allowing for unauthorized reading, writing, or deletion of files. This is a legacy vulnerability originally reported in 1997.

Affected products

  • Washington University wu-ftpd

Timeline

  • 1997-07-01: disclosed: Initial publication date in NVD.

References

Related threats