Login
Newsletter
Werbung

Sicherheit: Ausführung von beliebigem SQL-Code in proftpd
Aktuelle Meldungen Distributionen
Name: Ausführung von beliebigem SQL-Code in proftpd
ID: 200306-10
Distribution: Gentoo
Plattformen: Keine Angabe
Datum: Do, 26. Juni 2003, 13:00
Referenzen: Keine Angabe
Applikationen: ProFTPD

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

--------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-10
--------------------------------------------------------------------

          PACKAGE : proftpd
          SUMMARY : sql injection
             DATE : 2003-06-25 21:48 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <proftpd-1.2.9_rc1
    FIXED VERSION : >=proftpd-1.2.9_rc1
              CVE :

--------------------------------------------------------------------

from advisory:

"A SQL Inject exists in ProFTPD server using the mod_sql module to
authenticate against PostgreSQL database server. This vulnerability
may allow a remote user to login whithout user and password."

Read the full advisory at
http://marc.theaimsgroup.com/?l=full-disclosure&m=105597431408016&w=2

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-ftp/proftpd upgrade to proftpd-1.2.9_rc1 as follows

emerge sync
emerge proftpd
emerge clean

--------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
--------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE++hihfT7nyhUpoZMRAloZAKCVu0S/hqDUntFwXrF6zsCwvdxWdgCguN29
Ysxuc1iu1W3nWMhqD2DlrGs=
=AktX
-----END PGP SIGNATURE-----
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung