FreeBSD Security Advisory: FreeBSD-SA-99:03.ftpd (fwd)
Bodnar Istvan
piggy at nostromo.jpte.hu
1999. Sze. 7., K, 23:49:54 CEST
Hello,
bocs, ha valaki mar megkapta, de nem art tudni.
---------- Forwarded message ----------
Date: Tue, 7 Sep 1999 10:20:19 -0600 (MDT)
From: FreeBSD Security Officer <security-officer at FreeBSD.ORG>
To: security-officer at FreeBSD.ORG
Subject: FreeBSD Security Advisory: FreeBSD-SA-99:03.ftpd
-----BEGIN PGP SIGNED MESSAGE-----
=============================================================================
FreeBSD-SA-99:03 Security Advisory
FreeBSD, Inc.
Topic: Two ftp daemons in ports vulnerable to attack.
Category: ports
Module: wu-ftpd and proftpd
Announced: 1999-09-05
Affects: FreeBSD 3.2 (and earlier)
FreeBSD-current before the correction date.
Corrected: FreeBSD-3.3 RELEASE
FreeBSD-current as of 1999/08/30
FreeBSD only: NO
Patches: NONE
I. Background
wuftpd and proftpd have a flaw which can lead to a remote root
compromise. They are both vulnerable since they are both based on a
code base that is vulnerable.
II. Problem Description
Remote users can gain root via a buffer overflow.
III. Impact
Remote users can gain root.
IV. Workaround
Disable the ftp daemon until you can upgrade your system.
V. Solution
Upgrade your wu-ftpd or proftpd ports to the most recent versions (any
version after August 30, 1999 is not impacted by this problem). If
you are running non-port versions, you should verify that your version
is not vulnerable or upgrade to using the ports version of these
programs.
=============================================================================
FreeBSD, Inc.
Web Site: http://www.freebsd.org/
Confidential contacts: security-officer at freebsd.org
Security notifications: security-notifications at freebsd.org
Security public discussion: freebsd-security at freebsd.org
PGP Key: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/public_key.asc
Notice: Any patches in this document may not apply cleanly due to
modifications caused by digital signature or mailer software.
Please reference the URL listed at the top of this document
for original copies of all patches if necessary.
=============================================================================
További információk a(z) BSD levelezőlistáról