CVE-2004-0042

NameCVE-2004-0042
Descriptionvsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vsftpd (PTS)jessie3.0.2-17+deb8u1fixed
stretch3.0.3-8fixed
buster, bullseye3.0.3-12fixed
bookworm3.0.3-13fixed
sid, trixie3.0.3-13.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vsftpdsource(unstable)2.0.1-1

Notes

can't find any mention of the bug being fixed, but vsftpd doesn't
show the beaviour described in http://www.securitytracker.com/alerts/2004/Jan/1008628.html

Search for package or bug name: Reporting problems