New vulnerability in wu-ftpd (CAN-2004-0148)

Rajesh Somasundaran <[email protected]> Fri, 19 Mar 2004 19:16:59 +0530
Newsgroups gmane.network.ftp.wuftpd.user,gmane.network.ftp.wuftpd.devel
Organization Hewlett Packard - ISO, Bangalore, India.
Message-ID <[email protected]>
Hello,

I saw a new security vulnerability reported on wu-ftpd (CERT advisory 
note CAN-2004-0148). I read it from 
http://www.cert-ist.com/english/advisories/listeavis_en.htm along with 
the s/key vulnerability.

CAN-2004-0148 Description:  wu-ftpd 2.6.2 and earlier, with the 
restricted-gid option enabled, allows local users to bypass access 
restrictions by changing the permissions to prevent access to their home 
directory, which causes wu-ftpd to use the root directory instead.

Is there any patch available for this vulnerability? I couldn't see any 
in www.wu-ftpd.org !!!

Thanks,
Rajesh.