Junglewise Threat Intelligence

CVE-1999-1298: FreeBSD Sysinstall insecure ftp user creation

CVE-1999-1298 · Severity: high · CVSS 7.5 · Published 1997-04-07

Technologies: FreeBSD Project Freebsd.

Executive brief

A vulnerability in the FreeBSD installation utility could allow unauthorized access to system resources. When setting up anonymous file sharing (FTP), the system incorrectly created a user account without a password. This could allow remote attackers to connect to the server and potentially disrupt operations or access sensitive information.

Technical details

The FreeBSD 'sysinstall' utility contains a configuration flaw when enabling anonymous FTP services. It creates the 'ftp' system account with an empty password field and assigns '/bin/date' as the login shell. While the use of '/bin/date' as a shell is intended to limit the user's capabilities, the lack of a password allows unauthenticated remote attackers to connect via services that do not strictly validate the shell's interactive capabilities. This can lead to unauthorized access to system resources or information disclosure. The issue was addressed in FreeBSD security advisory SA-97:03.

Affected products

  • FreeBSD Project FreeBSD 2.2.1 and earlier

Timeline

  • 1997-04-07: disclosed: Initial NVD publication date
  • 1997-04-07: advisory: FreeBSD-SA-97:03 issued

References