Mandrake Linux Security Advisory : proftpd (MDKSA-2003:095-1)

This script is Copyright (C) 2004-2013 Tenable Network Security, Inc.


Synopsis :

The remote Mandrake Linux host is missing one or more security
updates.

Description :

A vulnerability was discovered by X-Force Research at ISS in ProFTPD's
handling of ASCII translation. An attacker, by downloading a carefully
crafted file, can remotely exploit this bug to create a root shell.

The ProFTPD team encourages all users to upgrade to version 1.2.7 or
higher. The problematic code first appeared in ProFTPD 1.2.7rc1, and
the provided packages are all patched by the ProFTPD team to protect
against this vulnerability.

Update :

The previous update had a bug where the new packages would terminate
with a SIGNAL 11 when the command 'NLST -alL' was performed in certain
cases, such as if the size of the output of the command was greater
than 1024 bytes.

These updated packages have a fix applied to prevent this crash.

See also :

http://bugs.proftpd.org/show_bug.cgi?id=2194
http://xforce.iss.net/xforce/alerts/id/154

Solution :

Update the affected proftpd and / or proftpd-anonymous packages.

Risk factor :

High / CVSS Base Score : 9.0
(CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C)

Family: Mandriva Local Security Checks

Nessus Plugin ID: 14077 (mandrake_MDKSA-2003-095.nasl)

Bugtraq ID:

CVE ID: CVE-2003-0831

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now