Package: wu-ftpd (wu-ftpd-academ)
Vulnerability: remote root exploit
Debian-specific: no
The version of wu-ftpd distributed in Debian GNU/Linux 2.1 (a.k.a. slink),
as well as in the frozen (potato) and unstable (woody) distributions, is
vulnerable to a remote root compromise. The default configuration in all
current Debian packages prevents the currently available exploits in the
case of anonymous access, although local users could still possibly
compromise the server.
This has been fixed in versions 2.4.2.16-13.1 (for slink) and 2.6.0-5.1 (for
potato and woody), and we recommend that you update your wu-ftpd-academ (for
slink) or wu-ftpd (for potato and woody) package immediately.
Debian GNU/Linux 2.1 alias slink
This version of Debian was released only for Intel ia32, the Motorola
680x0, the Alpha, and the Sun Sparc architecture. Fixes for Intel ia32
and the Sun Sparc architecture are currently available; fixes for other
architectures will be available soon.
Source archives:
MD...
Get the latest Linux and open source security news straight to your inbox.