Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

proftpd
200306-10
Published: 2003-06-25 22:24:41
Updated: 2003-06-25 22:24:41

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-10
- - - ---------------------------------------------------------------------

          PACKAGE : proftpd
          SUMMARY : sql injection
             DATE : 2003-06-25 21:48 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <proftpd-1.2.9_rc1
    FIXED VERSION : >=proftpd-1.2.9_rc1
              CVE :

- - - ---------------------------------------------------------------------

from advisory:

"A SQL Inject exists in ProFTPD server using the mod_sql module to
authenticate against PostgreSQL database server. This vulnerability
may allow a remote user to login whithout user and password."

Read the full advisory at
http://marc.theaimsgroup.com/?l=full-disclosure&m=105597431408016&w=2

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-ftp/proftpd upgrade to proftpd-1.2.9_rc1 as follows

emerge sync
emerge proftpd
emerge clean

- - - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
- - - ---------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE++hihfT7nyhUpoZMRAloZAKCVu0S/hqDUntFwXrF6zsCwvdxWdgCguN29
Ysxuc1iu1W3nWMhqD2DlrGs=
=AktX
-----END PGP SIGNATURE-----







 

Privacy Statement
Copyright 2008, SecurityFocus