Local Privilege Escalation in ProFTPd due to Password Logging Issue
CVE-1999-1475

Currently unrated

Key Information:

Status
Vendor
CVE Published:
19 November 1999

What is CVE-1999-1475?

The ProFTPd server version 1.2, when compiled with the mod_sqlpw module, has a significant vulnerability where it logs user passwords in the wtmp log file. This allows local users to gain unauthorized access to sensitive credentials. As these passwords can be retrieved using the last command or similar methods, it poses a serious security risk, enabling potential privilege escalation for users with access to the log file.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.