2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2004-0148" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2004-04-15T04:00:00.000" ,
"lastModified" : "2018-05-03T01:29:24.020" ,
"vulnStatus" : "Modified" ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead."
} ,
{
"lang" : "es" ,
"value" : "wu-ftpd 2.6.2 y anteriores, con la opci\u00f3n restricted-gid activada, permite a usuarios locales saltarse restricciones de acceso cambiando los permisos para impedir el acceso a su directorio home, lo que hace que wu-ftpd use el directorio ra\u00edz en su lugar."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C" ,
"accessVector" : "LOCAL" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
"availabilityImpact" : "COMPLETE" ,
"baseScore" : 7.2
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : true ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sgi:propack:2.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "26430687-409B-448F-934B-06AB937DDF63"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sgi:propack:2.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0702A32E-E577-403C-B4D9-15037D7100A5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "28E5257A-F5ED-482C-9A0B-3B576513E7D7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta2:*:academ:*:*:*:*:*" ,
"matchCriteriaId" : "833542E5-B4E7-4995-95C9-E012AE13902D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18:*:academ:*:*:*:*:*" ,
"matchCriteriaId" : "C63ACBE3-5BB2-483E-A5FE-87698E98354A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B39D46C4-B153-4301-AE9C-57FB6BA64CD9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E55582DD-DEF7-4BF8-950C-E7E58BD29DE5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FF9B9132-19A1-4242-A129-E5A49F466EA2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4B9E32F3-06CF-482D-8313-3D098CDE8B6B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0A096214-84AD-44F5-BBEF-F9F17B9B0C43"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4989799F-143A-45E5-A30C-9E3203649770"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1E3D0CC6-D1A0-4784-BE93-319C7EE59134"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4FA32489-F098-43D2-80B7-89CFE0BE9A3A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "91C6388E-464B-4562-BC7B-7B4A66387B30"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "923B5711-853D-4A77-8FB3-D5C3D449518D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9BB1B136-F90E-426B-8010-F2D059E89DBE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr15:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD9EFCD7-2A13-420E-B6A0-C1248B2E6E2F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr16:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "573486C8-0349-4BC9-AD7D-3FBF93DDB6AF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.4.2_vr17:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CAD81A30-9C35-4EEA-B6FE-A4AC76893AC6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "473E71DD-F779-4F93-838A-AD6768BB8DFC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C5E9B738-E8DF-4FE7-B4A5-91DE46A9CF8F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7196CF2D-8CCC-454A-A2C1-6408A9D636C5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:washington_university:wu-ftpd:2.6.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D851CEBD-4FE5-46D9-99BD-CA3F3235B2E6"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://marc.info/?l=bugtraq&m=108999466902690&w=2" ,
"source" : "cve@mitre.org"
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/11055" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://secunia.com/advisories/20168" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.debian.org/security/2004/dsa-457" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.frsirt.com/english/advisories/2006/1867" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.redhat.com/support/errata/RHSA-2004-096.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/9832" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/15423" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1147" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1636" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1637" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A648" ,
"source" : "cve@mitre.org"
}
]
}