First published: Wed Jan 14 2004(Updated: )
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vsftpd | =1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0042 is classified as a medium severity vulnerability.
To fix CVE-2004-0042, upgrade to a newer version of vsftpd that eliminates the error message disclosure issue.
CVE-2004-0042 allows attackers to discern valid usernames, potentially facilitating targeted attacks.
CVE-2004-0042 specifically affects vsftpd version 1.1.3.
Users and administrators of vsftpd 1.1.3 are affected by CVE-2004-0042.