Junglewise Threat Intelligence

CVE-1999-0498: Generic TFTP Server directory traversal and information disclosure

CVE-1999-0498 · Severity: critical · CVSS 10 · Published 1991-09-27

Vendors: Generic.

Executive brief

A vulnerability exists in certain Trivial File Transfer Protocol (TFTP) servers where the service is not restricted to a specific folder. This allows a remote attacker to download sensitive system files, such as password databases, from anywhere on the server's hard drive. This could lead to a complete compromise of the system and the theft of user credentials.

Technical details

The TFTP (Trivial File Transfer Protocol) daemon is misconfigured or lacks a 'chroot' or directory restriction mechanism. Because TFTP typically does not require authentication, a remote attacker can use standard TFTP GET commands to retrieve any file that the service process has permissions to read. This frequently includes sensitive files like /etc/passwd on Unix-like systems. The vulnerability is exploited over the network (UDP port 69) without any prior credentials or user interaction. Mitigation involves configuring the TFTP server to run in a secure, isolated directory (secure mode).

Affected products

  • Generic TFTP Server

Timeline

  • 1991-09-27: disclosed: Initial publication date in NVD

References