CVE
- Id
- 524
- CVE No.
- CVE-1999-0527
- Status
- Candidate
- Description
- The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.
- Phase
- Proposed (19990803)
- Votes
- ACCEPT(3) Baker, Northcutt, Wall | MODIFY(1) Frech
- Comments
- Northcutt> That that starts to get specific :) | Frech> ftp-writable-directory(6253) | ftp-write(53) | "writeable" in the description should be "writable."