First published: Wed Jan 01 1997(Updated: )
The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
wu-ftpd | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0202 is considered a high-severity vulnerability as it allows arbitrary command execution on the system during FTP sessions.
To fix CVE-1999-0202, upgrade the wu-ftpd to version 2.4.2 or later, which addresses this security issue.
CVE-1999-0202 exploits a flaw in the GNU tar command used within FTP sessions that can lead to unauthorized command execution.
CVE-1999-0202 affects wu-ftpd version 2.4.1, allowing potential attacks during FTP session handling.
Mitigation of CVE-1999-0202 without an upgrade is difficult, but limiting FTP access or using alternative secure file transfer methods can reduce risk.