Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


[Bugdev] [Full-Disclosure] GLSA: net-ftp/proftpd (200309-16)
.

  • To: [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED]
  • Subject: [Bugdev] [Full-Disclosure] GLSA: net-ftp/proftpd (200309-16)
  • From: [EMAIL PROTECTED] (Daniel Ahlberg)
  • Date: Mon, 29 Sep 2003 16:23:23 +0200 (CEST)
  • Reply-to: [EMAIL PROTECTED]
  • Sender: [EMAIL PROTECTED]
.
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-16
- ------------------------------------------------------------------------
          PACKAGE : net-ftp/proftpd
          SUMMARY : ASCII File Remote Compromise Vulnerability
             DATE : 2003-09-28 00:37 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <proftpd-1.2.9_rc2
    FIXED VERSION : =proftpd-1.2.9_rc2
    GENTOO BUG ID : 29452
              CVE : none that we are aware of at this time
- ------------------------------------------------------------------------

SUMMARY:

 ISS X-Force discovered a vulnerability that could be triggered when a
 specially crafted file is uploaded to a proftpd server.

 Read the full advisory at:
  http://www.proftpd.org/

SOLUTION:

 It is recommended that all Gentoo Linux users who are running
 net-ftp/proftpd upgrade to proftpd-1.29_rc2 as follows

 emerge sync
 emerge '>=net-ftp/proftpd-1.2.9_rc2'
 emerge clean

- - - ---------------------------------------------------------------------
[EMAIL PROTECTED]
[EMAIL PROTECTED] - GnuPG key is available at http://dev.gentoo.org/~aliz
- - - ---------------------------------------------------------------------

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQE/eEBbfT7nyhUpoZMRArDnAKCFlLbPmeC/S05/0EG1pqJc9BbClACgjPY6
OintOPB6pXf211OQxsUC7Tg=
=+hmK
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________
Bugdev mailing list
[EMAIL PROTECTED]
http://bugdev.avet.com.pl/
http://www.avet.com.pl/mailman/listinfo/bugdev

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.