WU-FTPD rnfr File Overwrite

high Nessus Plugin ID 14302

Synopsis

The remote FTP server has a file overwrite vulnerability.

Description

The remote WU-FTPD server seems to be vulnerable to a remote flaw.

This version contains a flaw that may allow a malicious user to overwrite arbitrary files. The issue is triggered when an attacker sends a specially formatted rnfr command. This flaw will allow a remote attacker to overwrite any file on the system.

*** Nessus solely relied on the banner of the remote server
*** to issue this warning, so it may be a false positive.

Solution

Upgrade to WU-FTPD 2.4.2 or newer.

Plugin Details

Severity: High

ID: 14302

File Name: wu_ftpd_rnfr_file_overwrite.nasl

Version: 1.16

Type: remote

Family: FTP

Published: 8/17/2004

Updated: 8/15/2018

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Information

Required KB Items: Settings/ParanoidReport, ftp/login, ftp/wuftpd

Vulnerability Publication Date: 8/27/1999

Reference Information

CVE: CVE-1999-0081