CVE-2004-0148: High severity washington university wu-ftpd vulnerability
wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0148?
CVE-2004-0148 has a moderate severity level, as it allows local users to bypass access restrictions.
How do I fix CVE-2004-0148?
To fix CVE-2004-0148, ensure that the restricted-gid option is configured correctly and limit permissions on user home directories as necessary.
Which versions of wu-ftpd are affected by CVE-2004-0148?
Versions 2.6.2 and earlier of wu-ftpd are affected by CVE-2004-0148.
Can CVE-2004-0148 be exploited remotely?
No, CVE-2004-0148 can only be exploited by local users who have access to the system.
What is the impact of CVE-2004-0148 on system security?
CVE-2004-0148 compromises system security by allowing unauthorized users to access files outside their home directories.