Re: [Bug 327] ProFTPD-1.2.8p
Dan Osterrath <[email protected]>
| Newsgroups | gmane.linux.lfs.security,gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
Am Freitag, 26. September 2003 15:16 schrieb [email protected]: > > "X-Force Research at ISS has discovered a remote exploit in ProFTPD's > handling of ASCII translations that an attacker, by downloading a carefully > crafted file, can exploit and gain a root shell. > > The source distributions on ftp.proftpd.org have all been replaced with > patched versions. All ProFTPD users are strongly urged to upgrade to one of > the patched versions as soon as possible." > Probably this should also go to LFS.security as some might not read BLFS.book. -- ---------------------------------------------------------------------- %> ln -s /dev/null /dev/brain %> ln -s /dev/urandom /dev/world %> dd if=/dev/world of=/dev/brain -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQA/dEKf9NbB8EM160MRAp77AJ9QOzBWfUVYmy3o8oQOf/Xx+UmHTwCg9mLm xJb2KffIcqx8cIORexuGD5U= =M9AP -----END PGP SIGNATURE-----