CVE DATABASE / CVE-2004-0148
CVE-2004-0148
CVSS 7.2 · HIGH
Summary
wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.
CVSS 2.0 breakdown
| Base score | 7.2 (HIGH) |
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| Attack vector | LOCAL |
| Attack complexity | LOW |
| Confidentiality | COMPLETE |
| Integrity | COMPLETE |
| Availability | COMPLETE |
Affected products
Sgi propackWashington_university wu-ftpd
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://marc.info/?l=bugtraq&m=108999466902690&w=2
- http://secunia.com/advisories/11055
- http://secunia.com/advisories/20168
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1
- http://www.debian.org/security/2004/dsa-457
- http://www.frsirt.com/english/advisories/2006/1867
- http://www.redhat.com/support/errata/RHSA-2004-096.html
- http://www.securityfocus.com/bid/9832
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15423
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1147
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1636
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1637
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A648
Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.