CVE

Id
8470  
CVE No.
CVE-2004-0042  
Status
Candidate  
Description
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.  
Phase
Modified (20050526)  
Votes
ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Wall, Williams | REJECT(1) Cox  
Comments
Williams> insufficient data. | CHANGE> [Cox changed vote from REVIEWING to REJECT] | Cox> Expected behaviour. By source code analysis the difference in | behaviour mentioned in the report only occurs when an administrator has | configured the server with an explicit userlist - either to allow or deny | all users in the userlist. The vsftpd manual page states that if a | userlist is used then the user will be denied access before they are asked | for a password to help prevent cleartext passwords being transmitted. | Administrators who don"t want this behaviour do not need to configure an | optional userlist.