Release Date: 2004-03-04
Critical:
Highly critical
Impact: System access
Where: From remote
Software: ProFTPD 1.2.x
Description:
Phantasmal Phantasmagoria has reported a vulnerability in ProFTPD, which potentially can be exploited by malicious users to compromise a vulnerable system.
The vulnerability is caused due to two off-by-one errors in the "_xlate_ascii_write()" function. These can be exploited by sending a specially crafted "RETR" FTP command with a 1023 bytes long argument starting with a linefeed character.
Successful exploitation may allow execution of arbitrary code with the privileges of ProFTPD.
The vulnerability has been reported in the following versions:
* 1.2.7/1.2.7p
* 1.2.8/1.2.8p
* 1.2.9rc1/1.2.9rc1p
* 1.2.9rc2/1.2.9rc2p
Solution:
The vulnerabilities are reportedly not present in version 1.2.9rc3 and later.
http://www.proftpd.org/download.html
Provided and/or discovered by:
Phantasmal Phantasmagoria
Please note: The information, which this Secunia Advisory is based upon, comes from third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.




