CVE-1999-1090: High severity NCSA Telnet vulnerability
The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable FTP in the NCSA Telnet configuration: remove any 'ftp=yes' line (or otherwise ensure FTP is not enabled) so the FTP service cannot be used to read or modify files.
NCSA Telnet ftp = disabled - Compensating control
Until FTP is disabled in NCSA Telnet, restrict or block access to its FTP functionality from untrusted networks (for example via firewall rules or network ACLs limiting access to trusted hosts/networks).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1090?
CVE-1999-1090 is considered a high severity vulnerability due to the potential for remote file access by attackers.
How do I fix CVE-1999-1090?
To fix CVE-1999-1090, disable FTP support in the NCSA Telnet configuration or update to a patched version that addresses this issue.
What systems are affected by CVE-1999-1090?
CVE-1999-1090 affects versions of the NCSA Telnet package for Macintosh and PC.
What kind of attacks can occur due to CVE-1999-1090?
Attackers can exploit CVE-1999-1090 to read and modify arbitrary files on the affected systems.
Is there a workaround for CVE-1999-1090?
A temporary workaround for CVE-1999-1090 is to ensure that FTP is not enabled in any configuration used.