Re: [Bug 327] ProFTPD-1.2.8p

Dan Osterrath <[email protected]>
Newsgroups gmane.linux.lfs.security,gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
Am Freitag, 26. September 2003 15:16 schrieb [email protected]:
>
> "X-Force Research at ISS has discovered a remote exploit in ProFTPD's
> handling of ASCII translations that an attacker, by downloading a carefully
> crafted file, can exploit and gain a root shell.
>
> The source distributions on ftp.proftpd.org have all been replaced with
> patched versions. All ProFTPD users are strongly urged to upgrade to one of
> the patched versions as soon as possible."
>

Probably this should also go to LFS.security as some might not read BLFS.book.

-- 
----------------------------------------------------------------------
%> ln -s /dev/null /dev/brain
%> ln -s /dev/urandom /dev/world
%> dd if=/dev/world of=/dev/brain

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQA/dEKf9NbB8EM160MRAp77AJ9QOzBWfUVYmy3o8oQOf/Xx+UmHTwCg9mLm
xJb2KffIcqx8cIORexuGD5U=
=M9AP
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.