ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-02-20T05:00:00
Updated: 2024-08-08T01:00:36.524Z
Reserved: 2005-02-20T00:00:00
Link: CVE-2004-1602
Vulnrichment
No data.
NVD
Status : Modified
Published: 2004-10-15T04:00:00.000
Modified: 2024-11-20T23:51:17.900
Link: CVE-2004-1602
Redhat
No data.