CVE-1999-1298: Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and wit

Published n/a Updated 2026-08-21T04:30:38.010Z

Summary

Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.

Severity

UNKNOWN

Source Attribution

Source: NVD · Updated: 2026-08-21T04:30:38.010Z · Confidence: high

Impact

Based on CVSS vector: n/a — assess confidentiality, integrity, and availability impact via the official vector documentation.

Affected Software

Fix

Upgrade affected software to the fixed version identified above. Apply vendor patches and monitor advisories before exposed systems go unpatched.

References