- ------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-16
- ------------------------------------------------------------------------
          PACKAGE : net-ftp/proftpd
          SUMMARY : ASCII File Remote Compromise Vulnerability
             DATE : 2003-09-28 00:37 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <proftpd-1.2.9_rc2
    FIXED VERSION : =proftpd-1.2.9_rc2
    GENTOO BUG ID : 29452
              CVE : none that we are aware of at this time
- ------------------------------------------------------------------------

SUMMARY:

 ISS X-Force discovered a vulnerability that could be triggered when a
 specially crafted file is uploaded to a proftpd server.

 Read the full advisory at:
   The ProFTPD Project: Home

SOLUTION:

 It is recommended that all Gentoo Linux users who are running
 net-ftp/proftpd upgrade to proftpd-1.29_rc2 as follows

 emerge sync
 emerge '>=net-ftp/proftpd-1.2.9_rc2'
 emerge clean

- - - ---------------------------------------------------------------------
solar@gentoo.org
aliz@gentoo.org - GnuPG key is available at   
- - - ---------------------------------------------------------------------



Gentoo: net-ftp/proftpd Remote file compromise vulnerability

ISS X-Force discovered a vulnerability that could be triggered when a specially crafted file is uploaded to a proftpd server.

Summary


- ------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-16
- ------------------------------------------------------------------------
    FIXED VERSION : =proftpd-1.2.9_rc2
    GENTOO BUG ID : 29452
- ------------------------------------------------------------------------
SUMMARY:

ISS X-Force discovered a vulnerability that could be triggered when a specially crafted file is uploaded to a proftpd server.
Read the full advisory at: The ProFTPD Project: Home
SOLUTION:
It is recommended that all Gentoo Linux users who are running net-ftp/proftpd upgrade to proftpd-1.29_rc2 as follows
emerge sync emerge '>=net-ftp/proftpd-1.2.9_rc2' emerge clean
solar@gentoo.org aliz@gentoo.org - GnuPG key is available at


Resolution

References

Availability

Concerns

Severity
PACKAGE : net-ftp/proftpd
SUMMARY : ASCII File Remote Compromise Vulnerability
DATE : 2003-09-28 00:37 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <proftpd-1.2.9_rc2
CVE : none that we are aware of at this time

Synopsis

Background

Affected Packages

Impact

Workaround

Related News