Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://marc.info/?l=bugtraq&m=93923873006014&w=2 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2001-09-12T04:00:00
Updated: 2024-08-01T17:11:03.038Z
Reserved: 2001-08-31T00:00:00
Link: CVE-1999-1345
Vulnrichment
No data.
NVD
Status : Modified
Published: 1999-10-05T04:00:00.000
Modified: 2024-11-20T23:30:53.450
Link: CVE-1999-1345
Redhat
No data.