CVE
- Id
- 3575
- CVE No.
- CVE-2001-0768
- Status
- Candidate
- Description
- GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.
- Phase
- Proposed (20011012)
- Votes
- ACCEPT(2) Baker, Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall
- Comments
- Baker> Vendor added password encryption in latest version, 0.996, and you can see the comments in the changes log, at the following URL: | | www.nitrolic.com/main.htm | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002