RHEL 2.1 : wu-ftpd (RHSA-2004:096)

critical Nessus Plugin ID 12475

Synopsis

The remote Red Hat host is missing a security update.

Description

An updated wu-ftpd package that fixes two security issues is now available.

The wu-ftpd package contains the Washington University FTP (File Transfer Protocol) server daemon. FTP is a method of transferring files between machines.

Glenn Stewart discovered a flaw in wu-ftpd. When configured with 'restricted-gid home', an authorized user could use this flaw to circumvent the configured home directory restriction by using chmod.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0148 to this issue.

Michael Hendrickx found a flaw in the S/Key login handling. On servers using S/Key authentication, a remote attacker could overflow a buffer and potentially execute arbitrary code.

Users of wu-ftpd are advised to upgrade to this updated package, which contains backported security patches and is not vulnerable to these issues.

Solution

Update the affected wu-ftpd package.

See Also

https://access.redhat.com/security/cve/cve-2003-1329

https://access.redhat.com/security/cve/cve-2004-0148

https://access.redhat.com/security/cve/cve-2004-0185

http://www.securiteam.com/unixfocus/6X00Q1P8KC.html

https://access.redhat.com/errata/RHSA-2004:096

Plugin Details

Severity: Critical

ID: 12475

File Name: redhat-RHSA-2004-096.nasl

Version: 1.28

Type: local

Agent: unix

Published: 7/6/2004

Updated: 1/14/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:wu-ftpd, cpe:/o:redhat:enterprise_linux:2.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 3/8/2004

Vulnerability Publication Date: 12/31/2003

Reference Information

CVE: CVE-2003-1329, CVE-2004-0148, CVE-2004-0185

RHSA: 2004:096