CVE
- Id
- 8470
- CVE No.
- CVE-2004-0042
- Status
- Candidate
- Description
- vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
- Phase
- Modified (20050526)
- Votes
- ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Wall, Williams | REJECT(1) Cox
- Comments
- Williams> insufficient data. | CHANGE> [Cox changed vote from REVIEWING to REJECT] | Cox> Expected behaviour. By source code analysis the difference in | behaviour mentioned in the report only occurs when an administrator has | configured the server with an explicit userlist - either to allow or deny | all users in the userlist. The vsftpd manual page states that if a | userlist is used then the user will be denied access before they are asked | for a password to help prevent cleartext passwords being transmitted. | Administrators who don"t want this behaviour do not need to configure an | optional userlist.