|
From: Kurt Lieber <klieber@gentoo.org>
Date: Wed May 19 2004 - 08:03:40 EDT
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
Version 1.2.9 of ProFTPD introduced a vulnerability that causes
Background
ProFTPD is an FTP daemon.
Affected packages
-------------------------------------------------------------------
Description
ProFTPD 1.2.9 introduced a vulnerability that allows CIDR-based ACLs
Impact
This vulnerability may allow unauthorized files, including critical
Workaround
Users may work around the problem by avoiding use of CIDR-based ACLs.
Resolution
ProFTPD users are encouraged to upgrade to the latest version of the
# emerge sync
# emerge -pv ">=net-ftp/proftpd-1.2.9-r2"
References
[ 1 ] CAN-2004-0432
Availability
This GLSA and any updates to it are available for viewing at
http://security.gentoo.org/glsa/glsa-200405-09.xml
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the
License
Copyright 2004 Gentoo Technologies, Inc; referenced text
The contents of this document are licensed under the
http://creativecommons.org/licenses/by-sa/1.0
_______________________________________________
This archive was generated by hypermail 2.1.8 : Wed May 19 2004 - 09:07:22 EDT |
Custom Search
|