Jump to content

Advisories MDVSA-2010:227: proftpd


paul
 Share

Recommended Posts

Multiple vulnerabilities were discovered and corrected in proftpd:

 

Multiple directory traversal vulnerabilities in the mod_site_misc

module in ProFTPD before 1.3.3c allow remote authenticated users to

create directories, delete directories, create symlinks, and modify

file timestamps via directory traversal sequences in a (1) SITE

MKDIR, (2) SITE RMDIR, (3) SITE SYMLINK, or (4) SITE UTIME command

(CVE-2010-3867).

 

Multiple stack-based buffer overflows in the pr_netio_telnet_gets

function in netio.c in ProFTPD before 1.3.3c allow remote attackers

to execute arbitrary code via vectors involving a TELNET IAC escape

character to a (1) FTP or (2) FTPS server (CVE-2010-4221).

 

Packages for 2009.0 are provided as of the Extended Maintenance

Program. Please visit this link to learn more:

http://store.mandriva.com/product_info.php?cPath=149&products_id=490

 

The updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...