[Bug 672328] [NEW] vsftpd: discloses whether usernames are valid or not

2010-11-07 Thread Mark Hobley
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: vsftpd There is a bug in vsftpd daemon, which causes the system to skip asking for a password if the username is invalid. This enables a remote user to determine whether the enter user account names

[Bug 672328] [NEW] vsftpd: discloses whether usernames are valid or not

2010-11-07 Thread Mark Hobley
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: vsftpd There is a bug in vsftpd daemon, which causes the system to skip asking for a password if the username is invalid. This enables a remote user to determine whether the enter user account names