CVE-2003-1596
Summary
| CVE | CVE-2003-1596 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-05 15:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Novell | Netware | 5.1 | All | All | All |
| Operating System | Novell | Netware | 6.0 | All | All | All |
| Operating System | Novell | Netware | 6.5 | All | All | All |
| Application | Novell | Netware Ftp Server | 5.01i | All | All | All |
| Application | Novell | Netware Ftp Server | 5.01o | All | All | All |
| Application | Novell | Netware Ftp Server | 5.01w | All | All | All |
| Application | Novell | Netware Ftp Server | 5.01y | All | All | All |
| Application | Novell | Netware Ftp Server | 5.02b | All | All | All |
| Application | Novell | Netware Ftp Server | 5.02i | All | All | All |
| Application | Novell | Netware Ftp Server | 5.02r | All | All | All |
| Application | Novell | Netware Ftp Server | 5.02y | All | All | All |
| Application | Novell | Netware Ftp Server | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| What fixes are in NWFTPD.NLM v5.10.01, March 26, 2010? | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.