Re: New vulnerability in wu-ftpd (CAN-2004-0148)

Rajesh Somasundaran <[email protected]> Tue, 23 Mar 2004 12:59:48 +0530
Newsgroups gmane.network.ftp.wuftpd.devel,gmane.network.ftp.wuftpd.user
Organization Hewlett Packard - ISO, Bangalore, India.
Message-ID <[email protected]>
--------------030302090402030001040104
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

Hello,

I haven't received any responses yet on this matter. This is not the 
S/Key vulnerability I am talking about. This is a new security 
vulnerability reported in wu-ftpd. This seems to be very much critical; 
I have attached a small description of the same below.

Would greatly appreciate if some one could respond.

Thanks,
Rajesh.

Rajesh Somasundaran wrote:

> Hello,
>
> I saw a new security vulnerability reported on wu-ftpd (CERT advisory 
> note CAN-2004-0148). I read it from 
> http://www.cert-ist.com/english/advisories/listeavis_en.htm along with 
> the s/key vulnerability.
>
> CAN-2004-0148 Description:  wu-ftpd 2.6.2 and earlier, with the 
> restricted-gid option enabled, allows local users to bypass access 
> restrictions by changing the permissions to prevent access to their 
> home directory, which causes wu-ftpd to use the root directory instead.
>
> Is there any patch available for this vulnerability? I couldn't see 
> any in www.wu-ftpd.org !!!
>
> Thanks,
> Rajesh.


--------------030302090402030001040104
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1">
  <title></title>
</head>
<body>
Hello,<br>
<br>
I haven't received any responses yet on this matter. This is not the S/Key
vulnerability I am talking about. This is a new security vulnerability reported
in wu-ftpd. This seems to be very much critical; I have attached a small
description of the same below.<br>
<br>
Would greatly appreciate if some one could respond.<br>
<br>
Thanks,<br>
Rajesh.<br>
<br>
Rajesh Somasundaran wrote:<br>
<blockquote type="cite" cite="[email protected]">     
  <meta http-equiv="Content-Type" content="text/html;">
  <title></title>
     Hello,<br>
 <br>
 I saw a new security vulnerability reported on wu-ftpd (CERT advisory note 
CAN-2004-0148). I read it from <a class="moz-txt-link-freetext"
 href="http://www.cert-ist.com/english/advisories/listeavis_en.htm">http://www.cert-ist.com/english/advisories/listeavis_en.htm</a> 
along with the s/key vulnerability. <br>
 <br>
 CAN-2004-0148 <font size="2" face="Verdana, Arial, Helvetica, Geneva">Description:&nbsp;</font>
 <font size="2" face="Verdana, Arial, Helvetica, Geneva">wu-ftpd 2.6.2 and 
earlier, with the restricted-gid option enabled, allows local users to bypass 
access restrictions by changing the permissions to prevent access to their 
home directory, which causes wu-ftpd to use the root directory instead.</font><br>
 <br>
 Is there any patch available for this vulnerability? I couldn't see any
in <a class="moz-txt-link-abbreviated" href="http://www.wu-ftpd.org">www.wu-ftpd.org</a>
!!!<br>
 <br>
 Thanks,<br>
 Rajesh.<br>
 </blockquote>
</body>
</html>

--------------030302090402030001040104--