CVE-2004-1948

NameCVE-2004-1948
DescriptionNcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ncftp (PTS)buster2:3.2.5-2.1fixed
bullseye2:3.2.5-2.2fixed
sid, bookworm2:3.2.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ncftpsource(unstable)2:3.1.8-1low

Search for package or bug name: Reporting problems