CVE-2004-0148
Title: wu-ftpd restricted-gid access restrictions bypass
Access Restrictions Bypass
Proof Of Concept
No public PoC currently indexed for CVE-2004-0148.
CWE Category
NVD-CWE-noinfo
Published Date
Apr 15, 2004
Modified Date
Apr 03, 2025
Exploit Status
Not Found
Score
7.2
CVSS v2.0
Exploit Probability (EPSS)
0.03%
Vulnerability Summary
CVE-2004-0148: wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.
Impacted Vendors
Reference Links
http://marc.info/?l=bugtraq&m=108999466902690&w=2
http://secunia.com/advisories/11055
http://secunia.com/advisories/20168
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1
http://www.debian.org/security/2004/dsa-457
http://www.frsirt.com/english/advisories/2006/1867
http://www.redhat.com/support/errata/RHSA-2004-096.html
http://www.securityfocus.com/bid/9832
https://exchange.xforce.ibmcloud.com/vulnerabilities/15423
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1147
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1636
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1637
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A648
http://marc.info/?l=bugtraq&m=108999466902690&w=2
http://secunia.com/advisories/11055
http://secunia.com/advisories/20168
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1
http://www.debian.org/security/2004/dsa-457
http://www.frsirt.com/english/advisories/2006/1867
http://www.redhat.com/support/errata/RHSA-2004-096.html
http://www.securityfocus.com/bid/9832
https://exchange.xforce.ibmcloud.com/vulnerabilities/15423
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1147
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1636
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1637
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A648
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
7.2
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:L/AC:L/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2004-0148 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:L/AC:L/Au:N/C:C/I:C/A:C
Affected Stack
No specific products linked.