CVE

Id
3575  
CVE No.
CVE-2001-0768  
Status
Candidate  
Description
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.  
Phase
Proposed (20011012)  
Votes
ACCEPT(2) Baker, Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  
Comments
Baker> Vendor added password encryption in latest version, 0.996, and you can see the comments in the changes log, at the following URL: | | www.nitrolic.com/main.htm | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002