CVE-2004-0148

Summary

CVECVE-2004-0148
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2004-04-15 04:00:00 UTC
Updated2018-05-03 01:29:00 UTC
Descriptionwu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.

Risk And Classification

Problem Types: NVD-CWE-Other

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Sgi Propack 2.3 All All All
Application Sgi Propack 2.4 All All All
Application Sgi Propack 2.3 All All All
Application Sgi Propack 2.4 All All All
Application Washington University Wu-ftpd 2.4.1 All All All
Application Washington University Wu-ftpd 2.4.2_beta18 All academ All
Application Washington University Wu-ftpd 2.4.2_beta18_vr10 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr11 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr12 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr13 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr14 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr15 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr4 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr5 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr6 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr7 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr8 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr9 All All All
Application Washington University Wu-ftpd 2.4.2_beta2 All academ All
Application Washington University Wu-ftpd 2.4.2_vr16 All All All
Application Washington University Wu-ftpd 2.4.2_vr17 All All All
Application Washington University Wu-ftpd 2.5.0 All All All
Application Washington University Wu-ftpd 2.6.0 All All All
Application Washington University Wu-ftpd 2.6.1 All All All
Application Washington University Wu-ftpd 2.6.2 All All All
Application Washington University Wu-ftpd 2.4.1 All All All
Application Washington University Wu-ftpd 2.4.2_beta18 All academ All
Application Washington University Wu-ftpd 2.4.2_beta18_vr10 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr11 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr12 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr13 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr14 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr15 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr4 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr5 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr6 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr7 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr8 All All All
Application Washington University Wu-ftpd 2.4.2_beta18_vr9 All All All
Application Washington University Wu-ftpd 2.4.2_beta2 All academ All
Application Washington University Wu-ftpd 2.4.2_vr16 All All All
Application Washington University Wu-ftpd 2.4.2_vr17 All All All
Application Washington University Wu-ftpd 2.5.0 All All All
Application Washington University Wu-ftpd 2.6.0 All All All
Application Washington University Wu-ftpd 2.6.1 All All All
Application Washington University Wu-ftpd 2.6.2 All All All

References

ReferenceSourceLinkTags
Debian -- Security Information -- DSA-457-1 wu-ftpd DEBIAN www.debian.org Patch, Vendor Advisory
redhat.com | Red Hat Support REDHAT www.redhat.com Patch, Vendor Advisory
Repository / Oval Repository OVAL oval.cisecurity.org
Félicitations ! Votre domaine a bien été créé chez OVH ! FRSIRT www.frsirt.com
Secunia - Advisories - WU-FTPD Directory Access Restriction Bypass Vulnerability SECUNIA secunia.com
Repository / Oval Repository OVAL oval.cisecurity.org
Repository / Oval Repository OVAL oval.cisecurity.org
Repository / Oval Repository OVAL oval.cisecurity.org
IBM X-Force Exchange XF exchange.xforce.ibmcloud.com
'[security bulletin] SSRT4704 rev.0 HP-UX wu-ftpd local unauthorized access' - MARC HP marc.info
Solaris in.ftpd Directory Access Restriction Bypass Vulnerability - Advisories - Secunia SECUNIA secunia.com
#102356: Security Vulnerability in the Solaris 9 in.ftpd(1M) Server May Allow Unauthorized Directory Access SUNALERT sunsolve.sun.com
WU-FTPD restricted-gid Unauthorized Access Vulnerability BID www.securityfocus.com Patch, Vendor Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report