HIGH · 7.5

CVE-1999-0017

FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

Vulnerability Description

FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
GnuInet5.01
Washington UniversityWu-Ftpd2.4
CalderaOpenlinux1.2
FreebsdFreebsd1.0
IbmAix3.2
NetbsdNetbsd1.0
ScoOpen Desktop3.0
ScoOpenserver5.0.4
ScoUnixware2.1
SiemensReliant UnixAll versions
SunSunos4.1.3u1

References

FAQ

What is CVE-1999-0017?

CVE-1999-0017 is a vulnerability with a CVSS score of 7.5 (HIGH). FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

How severe is CVE-1999-0017?

CVE-1999-0017 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-1999-0017?

Check the references section above for vendor advisories and patch information. Affected products include: Gnu Inet, Washington University Wu-Ftpd, Caldera Openlinux, Freebsd Freebsd, Ibm Aix.