LWN.net Logo

wu-ftpd: insecure program execution

Package(s):wu-ftpd CVE #(s):CVE-1999-0997
Created:September 5, 2003 Updated:September 24, 2003
Description: wu-ftpd, an FTP server, implements a feature whereby multiple files can be fetched in the form of a dynamically constructed archive file, such as a tar archive. The names of the files to be included are passed as command line arguments to tar, without protection against them being interpreted as command-line options. GNU tar supports several command line options which can be abused, by means of this vulnerability, to execute arbitrary programs with the privileges of the wu-ftpd process.
Alerts:
Slackware SSA:2003-259-03 2003-09-23
Conectiva CLA-2003:748 2003-09-22
Debian DSA-377-1 2003-09-04

(Log in to post comments)

wu-ftpd: insecure program execution

Posted Oct 3, 2003 1:05 UTC (Fri) by wolfrider (guest, #3105) [Link]

I swear, I've seen so many security alerts for wu-ftpd... I honestly don't know why they just don't decomission it.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds