A remote exploit has been found in the FTP daemon, wu-ftpd. This can allow an attacker full access to your machine. . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1 - ----- Original Message -----From: "Slackware Security Team" To: Sent: Wednesday, June 28, 2000 5:18 AM Subject: [slackware-security] wu-ftpd remote exploit patched A remote exploit has been found in the FTP daemon, wu-ftpd. This can allow an attacker full access to your machine. The wu-ftpd daemon is part of the tcpip1.tgz package in the N series. A new tcpip1.tgz package is now available in the Slackware 7.1 tree. We have also provided a seperate patch package for users who have already installed Slackware 7.1 and just want the new FTP daemon. ======================================== wu-ftpd 2.6.0 AVAILABLE - (n6/tcpip1.tgz) ======================================== The recent root exploit in wu-ftpd has been patched and the new tcpip1.tgz is in the Slackware 7.1 tree: A seperate wu-ftpd-only patch package is available in the patches/ subdirectory: All users are strongly urged to upgrade to the patched wu-ftpd daemon. You only need to download one package to get the new FTP daemon. Here are the md5sums and checksums for the packages: 1660403894 62427 ./wu-ftpd-patch.tgz d42c1708634232f8bc6a396827959851 ./wu-ftpd-patch.tgz 3287743865 1017793 ./n6/tcpip1.tgz 7aff2b13086e881a6ee029d44a448f17 ./n6/tcpip1.tgz INSTALLATION INSTRUCTIONS FOR THE tcpip1.tgz PACKAGE: ---------------------------------------------------- If you have downloaded the new tcpip1.tgz package, you should bring the system into runlevel 1 and run upgradepkg on it: # telinit 1 # upgradepkg tcpip1.tgz # telinit 3 INSTALLATION INSTRUCTIONS FOR THE wu-ftpd-patch.tgz PACKAGE: ----------------------------------------------------------- If you have downloaded the wu-ftpd-patch.tgz package, you should bring the system into runlevel 1 and run installpkg on it: # telinit 1 # installpkg wu-ftpd-patch.tgz # telinit 3 Remember, it's also a good idea to backup configuration files before upgrading packages. - - Slackware Linux Security Team The Slackware Linux Project -----BEGIN PGP SIGNATURE-----Version: PGPfreeware 6.5.2 for non-commercial use iQA/AwUBOVollsngd47OM+yTEQIZsgCffHR0j80zHs9sl79XyZBtwBULuNsAn3mY tce8IvTDwbIul0DIFAbkees1 =mLB4 -----END PGP SIGNATURE----- . Critical alert regarding wu-ftpd identifies a flaw that allows unauthorized external access, resulting in potential takeover of your server.. Slackware Security, FTP Security Update, Remote Access Fix. . Severity: Critical. LinuxSecurity.com Team
A vulnerability involving an input validation error in the "site exec" command has recently been identified in the wu-ftpd program (CERT Advisory CA-2000-13). . A vulnerability involving an input validation error in the "site exec" command has recently been identified in the wu-ftpd program (CERT Advisory CA-2000-13). More information about this problem can be found at this site: 2000 CERT Advisories The wu-ftpd daemon is part of the tcpip1.tgz package in the N series. A new tcpip1.tgz package is now available in the Slackware -current tree. All users of Slackware 7.0, 7.1, and -current are stronly urged to upgrade to the new tcpip1.tgz package. For users of Slackware 4.0, a wuftpd.tgz patch package is being provided in the /patches tree of Slackware 4.0. ========================================wu-ftpd 2.6.1 AVAILABLE - (n1/tcpip1.tgz) ======================================== FOR USERS OF SLACKWARE 7.0, 7.1, and -current: --------------------------------------------- The recent vulnerability in wu-ftpd can be fixed by upgrading to the new tcpip1.tgz package. This package upgrades the wu-ftpd server to version 2.6.1. You can download it from the -current branch: All users of Slackware 7.0, 7.1, and -current are strongly urged to upgrade to the tcpip1.tgz package to fix the vulnerability in wu-ftpd. For verification purposes, we provide the following checksums: 16-bit "sum" checksum: 45865 995 128-bit MD5 message digest: 2ffec28ac4b9de34d5899f7cd88cc5c3 n1/tcpip1.tgz Installation instructions for the tcpip1.tgz package: If you have downloaded the new tcpip1.tgz package, you should bring the system into runlevel 1 and run upgradepkg on it: # telinit 1 # upgradepkg tcpip1.tgz # telinit 3 FOR USERS OF SLACKWARE 4.0: -------------------------- The recent vulnerability in wu-ftpd can be fixed by installing the wuftpd.tgz patchpackage. This package upgrades the wu-ftpd server to version 2.6.1. You can download it from the Slackware 4.0 branch: All users of Slackware 4.0 are strongly urged to install the wuftpd.tgz patch package to fix the vulnerability in wu-ftpd. For verification purposes, we provide the following checksums: 16-bit "sum" checksum: 06607 105 128-bit MD5 message digest: 75547b1762d7ff4fad233cd89529ff2c wuftpd.tgz Installation instructions for the wuftpd.tgz package: If you have downloaded the wuftpd.tgz patch package, you should bring the system into runlevel 1 and run installpkg on it: # telinit 1 # installpkg wuftpd.tgz # telinit 3 Remember, it's also a good idea to backup configuration files before upgrading packages. . An issue within the 'site exec' instruction of wu-ftpd necessitating patches for Slackware users to bolster protection.. Wu-Ftpd Update, Slackware Patch, Tcpip1 Update, Input Validation Error. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.