First published: Tue Jul 01 1997(Updated: )
wu-ftpd FTP daemon allows any user and password combination.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
wu-ftpd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0156 is considered a critical vulnerability due to its ability to allow unauthorized access to the FTP server.
CVE-1999-0156 allows any user to gain access to the wu-ftpd service regardless of the username or password provided.
To mitigate CVE-1999-0156, upgrade to a patched version of wu-ftpd that resolves the unauthorized access issue.
CVE-1999-0156 affects all versions of the wu-ftpd FTP daemon prior to the release that includes the fix for this vulnerability.
A temporary workaround for CVE-1999-0156 includes disabling the wu-ftpd service until a secure version is installed.