First published: Tue Apr 20 2004(Updated: )
NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ncftp Software Ncftp | =3.0.2 | |
Ncftp Software Ncftp | =3.1.3 | |
Ncftp Software Ncftp | =3.1.4 | |
Ncftp Software Ncftp | =3.0.0 | |
Ncftp Software Ncftp | =3.1.0 | |
Ncftp Software Ncftp | =3.0.3 | |
Ncftp Software Ncftp | =3.1.6 | |
Ncftp Software Ncftp | =3.1.5 | |
Ncftp Software Ncftp | =3.1.7 | |
Ncftp Software Ncftp | =3.1.1 | |
Ncftp Software Ncftp | =3.0.1 | |
Ncftp Software Ncftp | =3.1.2 | |
Ncftp Software Ncftp | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.