Summary
The remote host is missing an update as announced
via advisory SSA:2003-259-03.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=SSA:2003-259-03
Insight
Upgraded WU-FTPD packages are available for Slackware 9.0 and - -current. These fix a problem where an attacker could use a specially crafted filename in conjunction with WU-FTPD's conversion feature (mostly used to compress files, or produce tar archives) to execute arbitrary commands on the server.
In addition, a MAIL_ADMIN which has been found to be insecure has been disabled.
We do not recommend deploying WU-FTPD in situations where security is required.
Severity
Classification
-
CVE CVE-1999-0997 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities