CVE-1999-1411: High severity Debian Debian Linux vulnerability
The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
fsp 2.71-10 (Debian package)from your environment.Uninstall the fsp package version 2.71-10 from affected Debian systems if it is installed.
- Configuration
Disable anonymous FTP access in the wu-ftp configuration to prevent anonymous-user logins.
wu-ftp anonymous FTP access = disabled - Compensating control
Restrict access to FTP services at the network perimeter (firewall/ACL) to trusted IPs or networks to mitigate exposure if anonymous FTP becomes enabled.
- Operational
Inspect systems for an anonymous FTP user account added by the fsp package; if present, remove the account and notify administrators of the change.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1411?
CVE-1999-1411 is considered a moderate severity vulnerability.
How do I fix CVE-1999-1411?
To fix CVE-1999-1411, ensure that the anonymous FTP user is disabled in the FTP server configuration.
What systems are affected by CVE-1999-1411?
CVE-1999-1411 affects the Debian GNU/Linux 2.0 operating system specifically due to the fsp package installation.
What risks are posed by CVE-1999-1411?
CVE-1999-1411 poses risks of unauthorized file access through enabled anonymous FTP.
Is there a workaround for CVE-1999-1411?
A possible workaround for CVE-1999-1411 is to monitor FTP server logs to identify unauthorized access attempts.