Fedora 18 : proftpd-1.3.4b-5.fc18 (2013-0437)

This script is Copyright (C) 2013-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

Jann Horn reported that there is a possible race condition in the
handling of the MKD/XMKD FTP commands, when the UserOwner directive is
involved, and the attacker is on the same physical machine as a
running proftpd. This race applies to mod_sftp and the handling of the
MKDIR SFTP request as well.

Note that using the DefaultRoot directive to restrict sessions
mitigates this attack, since the symlinks created by the local
attacker will point outside of the chroot(2) area within the FTP
session, and thus the ownership change will fail. The default
configuration in Fedora applies the DefaultRoot directive to all users
except 'adm'.

The upstream reference for this issue is:
http://bugs.proftpd.org/show_bug.cgi?id=3841

This update includes upstream's backport to proftpd 1.3.4 of the fix
for this issue.

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://bugs.proftpd.org/show_bug.cgi?id=3841
https://bugzilla.redhat.com/show_bug.cgi?id=892715
http://www.nessus.org/u?3a7bfe84

Solution :

Update the affected proftpd package.

Risk factor :

Low / CVSS Base Score : 1.2
(CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:N)

Family: Fedora Local Security Checks

Nessus Plugin ID: 64365 ()

Bugtraq ID:

CVE ID: CVE-2012-6095

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now