Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Slackware: SSA:2003-259-02 Critical: ProFTPD Root Access Exploit

slackware
Calendar Grey September 23, 2003
Dist Slackware Esm H88
Updated versions of ProFTPD for Slackware counter a security flaw that could allow attackers to gain root access through crafted file submissions.
Upgraded ProFTPD packages are available for Slackware 8.1, 9.0 and-current

Summary

Here are the details from the Slackware 9.0 ChangeLog: Tue Sep 23 14:43:10 PDT 2003 n/proftpd-1.2.8p-i486-1.tgz: Upgraded to proftpd-1.2.8p (patched). This fixes a security problem in ProFTPD. From The ProFTPD Project: Home X-Force Research at ISS has discovered a remote exploit in ProFTPD's handling of ASCII translations that an attacker, by downloading a carefully crafted file, can exploit and gain a root shell. The source distributions on ftp.proftpd.org have all been replaced with patched versions. All ProFTPD users are strongly urged to upgrade to one of the patched versions as soon as possible. Note that the upgraded package does not change the displayed version number to 1.2.8p (it remains 1.2.8), but we've verified the source code to make sure that this is in fact the patched version. We recommend all sites running ProFTPD upgrade to the new package right away. (* Security fix *) WHERE TO FIND

Read the Full Advisory

Where Find New Packages

MD5 Signatures

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Related News

Your message here