CVE Vulnerabilities

CVE-1999-1298

Published: Apr 07, 1997 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd * 2.2.1 (including)
Freebsd Freebsd 2.1.0 (including) 2.1.0 (including)
Freebsd Freebsd 2.1.5 (including) 2.1.5 (including)
Freebsd Freebsd 2.1.6 (including) 2.1.6 (including)
Freebsd Freebsd 2.1.7 (including) 2.1.7 (including)
Freebsd Freebsd 2.2 (including) 2.2 (including)

References