Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Debian 4.0: DSA-1452-1 Critical: Wzdftpd Denial Of Service

debian
Calendar Grey January 6, 2008
Scroller Debian
Please update the wzdftpd package immediately to resolve a critical denial of service vulnerability impacting Debian systems. This action is crucial and requires prompt attention.
"k1tk4t" discovered that wzdftpd, a portable, modular, small and efficient ftp server, did not correctly handle the receipt of long usernames

Summary


For the old stable distribution (sarge), this problem has been fixed in
version 0.5.2-1.1sarge3.

For the unstable distribution (sid), this problem has been fixed in version
0.8.2-2.1.

We recommend that you upgrade your wzdftpd package.


Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge

Size/MD5 checksum: 818860 62a4af39801fe581f85cd063c5fc4717
Size/MD5 checksum: 769 56ce84eafc6683eae084c1edbe5a4567
Size/MD5 checksum: 8531 80784497bc6ccee3adc676584fe1df75

alpha architecture (DEC Alpha)

Size/MD5 checksum: 294...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.