Executive brief
A vulnerability in the FreeBSD installation utility could allow unauthorized access to system resources. When setting up anonymous file sharing (FTP), the system incorrectly created a user account without a password. This could allow remote attackers to connect to the server and potentially disrupt operations or access sensitive information.
Technical details
The FreeBSD 'sysinstall' utility contains a configuration flaw when enabling anonymous FTP services. It creates the 'ftp' system account with an empty password field and assigns '/bin/date' as the login shell. While the use of '/bin/date' as a shell is intended to limit the user's capabilities, the lack of a password allows unauthenticated remote attackers to connect via services that do not strictly validate the shell's interactive capabilities. This can lead to unauthorized access to system resources or information disclosure. The issue was addressed in FreeBSD security advisory SA-97:03.
Affected products
- FreeBSD Project FreeBSD 2.2.1 and earlier
Timeline
- 1997-04-07: disclosed: Initial NVD publication date
- 1997-04-07: advisory: FreeBSD-SA-97:03 issued