MEDIUM · 4.6

CVE-2004-1948

NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which dis...

Vulnerability Description

NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Ncftp SoftwareNcftp3.0.0

References

FAQ

What is CVE-2004-1948?

CVE-2004-1948 is a vulnerability with a CVSS score of 4.6 (MEDIUM). NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which dis...

How severe is CVE-2004-1948?

CVE-2004-1948 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1948?

Check the references section above for vendor advisories and patch information. Affected products include: Ncftp Software Ncftp.