Unrated severityNVD Advisory· Published Dec 20, 1999· Updated Apr 16, 2026
CVE-1999-0997
CVE-1999-0997
Description
wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
Affected products
7- cpe:2.3:a:millenux_gmbh:anonftp:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:wu-ftpd:2.4.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:university_of_washington:wu-ftpd:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:university_of_washington:wu-ftpd:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:university_of_washington:wu-ftpd:2.6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.