|
Gentoo: net-ftp/proftpd Remote file compromise vulnerability |
|
|
|
Posted by LinuxSecurity.com Team
|
ISS X-Force discovered a vulnerability that could be triggered when a specially crafted file is uploaded to a proftpd server.
- ------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-16
- ------------------------------------------------------------------------
PACKAGE : net-ftp/proftpd
SUMMARY : ASCII File Remote Compromise Vulnerability
DATE : 2003-09-28 00:37 UTC
EXPLOIT : remote
VERSIONS AFFECTED : http://www.proftpd.org/
SOLUTION:
It is recommended that all Gentoo Linux users who are running
net-ftp/proftpd upgrade to proftpd-1.29_rc2 as follows
emerge sync
emerge '>=net-ftp/proftpd-1.2.9_rc2'
emerge clean
- - - ---------------------------------------------------------------------
solar@gentoo.org
aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz
- - - ---------------------------------------------------------------------
|