CVE-2004-0042: Medium severity Beasts Vsftpd vulnerability
Published Jan 14, 2004
·Updated
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
Affected Software
1 affected component
Beasts Vsftpd=1.1.3
Event History
Jan 14, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0042?
CVE-2004-0042 is classified as a medium severity vulnerability.
2
How do I fix CVE-2004-0042?
To fix CVE-2004-0042, upgrade to a newer version of vsftpd that eliminates the error message disclosure issue.
3
What is the impact of CVE-2004-0042?
CVE-2004-0042 allows attackers to discern valid usernames, potentially facilitating targeted attacks.
4
Which versions of vsftpd are affected by CVE-2004-0042?
CVE-2004-0042 specifically affects vsftpd version 1.1.3.
5
Who is affected by CVE-2004-0042?
Users and administrators of vsftpd 1.1.3 are affected by CVE-2004-0042.