CVE-1999-1326: Medium severity washington university wu-ftpd vulnerability
wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wu-ftpdfrom your environment.Uninstall wu-ftpd from affected systems (or remove the package) until a vendor fix is available.
- Compensating control
Restrict access to the FTP service with network controls (firewall/ACL) so only trusted management IPs or internal networks can reach it; block external/untrusted networks to mitigate remote exploitation.
- Operational
Stop and disable the wu-ftpd service on affected hosts immediately to prevent exploitation until patched or replaced.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1326?
CVE-1999-1326 is considered a critical vulnerability due to its capability to allow unauthorized reading of arbitrary files.
How do I fix CVE-1999-1326?
To fix CVE-1999-1326, upgrade to a patched version of wu-ftpd that addresses the privilege drop issue.
What systems are affected by CVE-1999-1326?
CVE-1999-1326 primarily affects the wu-ftpd version 2.4 FTP server on various Unix-like operating systems.
Can CVE-1999-1326 be exploited remotely?
Yes, CVE-1999-1326 can potentially be exploited by remote attackers if they can issue the ABOR command during an active file transfer.
What is the impact of CVE-1999-1326?
The impact of CVE-1999-1326 is unauthorized access to sensitive files, which could lead to data breaches.