CVE
- Id
- 891
- CVE No.
- CVE-1999-0911
- Status
- Candidate
- Description
- Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
- Phase
- Modified (20050309)
- Votes
- ACCEPT(5) Baker, Blake, Cole, Prosser, Stracener | MODIFY(1) Frech | REVIEWING(1) Christey
- Comments
- Frech> XF:proftpd-long-dir-bo(3399) | Christey> Not absolutely sure if this isn"t the same as Palmetto | (CVE-1999-0368), which describes a similar type of overflow. | | NETBSD:NetBSD-SA1999-003 may refer to CVE-1999-0368: | ADDREF URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-003.txt.asc | Christey> ADDREF CIAC:J-068 | Include version numbers; too many wu-ftp/etc. problems | were published in summer/fall 1999