Gentoo Linux Security Advisory GLSA 200403-08
https://security.gentoo.org/
Severity: Normal
Title: oftpd DoS vulnerability
Date: March 29, 2004
Bugs: #45738
ID: 200403-08
Synopsis
=======
A remotely-exploitable overflow exists in oftpd, allowing an attacker
to crash the oftpd daemon.
Background
=========
Quote from
"oftpd is designed to be as secure as an anonymous FTP server can
possibly be. It runs as non-root for most of the time, and uses the
Unix chroot() command to hide most of the systems directories from
external users - they cannot change into them even if the server is
totally compromised! It contains its own directory change code, so that
it can run efficiently as a threaded server, and its own directory
listing code (most FTP servers execute the system "ls" command to list
files)."
Affected packages
================
------------------------------------------------------...
style>.gentoo_availability{display:block;}
Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3488470_4c9dbbdde36eef04251a4ced7eac4df9 on line 11
Get the latest Linux and open source security news straight to your inbox.