Debian: New wu-ftpd packages fix denial of service
Posted by Benjamin D. Thomas   
Debian Updated package.
Debian Security Advisory DSA 705-1
April 4th, 2005               
Package        : wu-ftpd
Vulnerability  : missing input sanitising
Problem-Type   : remote
Debian-specific: no
CVE IDs        : CAN-2005-0256 CAN-2003-0854

Several denial of service conditions have been discovered in wu-ftpd,
the popular FTP daemon.  The Common Vulnerabilities and Exposures
project identifies the following problems:


    Adam Zabrocki discovered a denial of service condition in wu-ftpd
    that could be exploited by a remote user and cause the server to
    slow down the server by resource exhaustion.


    Georgi Guninski discovered that /bin/ls may be called from within
    wu-ftpd in a way that will result in large memory consumption and
    hence slow down the server.

For the stable distribution (woody) these problems have been fixed in
version 2.6.2-3woody5.

For the unstable distribution (sid) these problems have been fixed in
version 2.6.2-19.

We recommend that you upgrade your wu-ftpd package.

Upgrade Instructions
wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody
For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list: