---
title: "CVE-2004-1948\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2004-1948?format=md
keywords: index, follow
---

# CVE-2004-1948

Publication date 20 April 2004

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

NcFTP client 3.1.6 and 3.1.7, when the username and password are included
in an FTP URL that is provided on the command line, allows local users to
obtain sensitive information via "ps aux," which displays the URL in the
process list.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ncftp | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1948)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2004-1948)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2004-1948)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2004-1948)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2004-1948>
