Lucene search

K
cve[email protected]CVE-1999-1345
HistorySep 12, 2001 - 4:00 a.m.

CVE-1999-1345

2001-09-1204:00:00
web.nvd.nist.gov
22
insecure permissions
auto_ftp 0.2
cve-1999-1345
nvd
local user access
script vulnerability

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.

Affected configurations

NVD
Node
auto_ftpauto_ftpMatch0.2
CPENameOperatorVersion
auto_ftp:auto_ftpauto ftpeq0.2

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-1999-1345