ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
http://securitytracker.com/id?1011687 | patch vdb entry exploit vendor advisory broken link third party advisory |
http://security.lss.hr/index.php?page=details&ID=LSS-2004-10-02 | patch exploit vendor advisory broken link |
http://www.securityfocus.com/bid/11430 | vdb entry exploit vendor advisory broken link third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17724 | third party advisory vdb entry |
http://marc.info/?l=bugtraq&m=109786760926133&w=2 | third party advisory mailing list |