Junglewise Threat Intelligence

CVE-1999-1090: NCSA Telnet insecure default configuration enables FTP server

CVE-1999-1090 · Severity: high · CVSS 7.5 · Published 1991-09-10

Vendors: Ncsa.

Executive brief

A vulnerability in the default configuration of NCSA Telnet for Macintosh and PC allows unauthorized remote access to files. By default, the software enables an FTP server even when not explicitly configured to do so, which could allow an attacker to read or modify sensitive files on the host system. This poses a significant risk to data confidentiality and integrity for users of this legacy networking tool.

Technical details

A configuration vulnerability exists in NCSA Telnet for Macintosh and PC where the FTP server component is enabled by default. Even in the absence of an explicit 'ftp=yes' directive in the configuration file, the software listens for FTP connections. A remote attacker can exploit this behavior to connect to the host and perform unauthorized file operations, including reading and modifying arbitrary files. This issue stems from insecure default settings rather than a code-level overflow or logic error. Users are advised to explicitly disable the service or update to a version where this default behavior is corrected.

Affected products

  • NCSA Telnet for Macintosh
  • NCSA Telnet for PC

Timeline

  • 1991-09-10: disclosed
  • 1991-09-10: advisory: NVD publication date

References