7.2
CVSSv2

CVE-2004-0148

Published: 15/04/2004 Updated: 03/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

wu-ftpd 2.6.2 and previous versions, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi propack 2.3

sgi propack 2.4

washington university wu-ftpd 2.4.2_beta18_vr14

washington university wu-ftpd 2.4.2_beta18_vr15

washington university wu-ftpd 2.4.2_beta2

washington university wu-ftpd 2.4.2_vr16

washington university wu-ftpd 2.4.2_beta18_vr10

washington university wu-ftpd 2.4.2_beta18_vr11

washington university wu-ftpd 2.4.2_beta18_vr6

washington university wu-ftpd 2.4.2_beta18_vr12

washington university wu-ftpd 2.4.2_beta18_vr13

washington university wu-ftpd 2.4.2_beta18_vr8

washington university wu-ftpd 2.4.2_beta18_vr9

washington university wu-ftpd 2.6.2

washington university wu-ftpd 2.4.2_beta18_vr7

washington university wu-ftpd 2.6.0

washington university wu-ftpd 2.6.1

washington university wu-ftpd 2.4.1

washington university wu-ftpd 2.4.2_beta18

washington university wu-ftpd 2.4.2_beta18_vr4

washington university wu-ftpd 2.4.2_beta18_vr5

washington university wu-ftpd 2.4.2_vr17

washington university wu-ftpd 2.5.0

Vendor Advisories

Two vulnerabilities were discovered in wu-ftpd: CAN-2004-0148 Glenn Stewart discovered that users could bypass the directory access restrictions imposed by the restricted-gid option by changing the permissions on their home directory On a subsequent login, when access to the user's home directory was denied, wu-ftpd would fall back to the ro ...