ProFTPD < 1.3.0rc2 Multiple Format Strings
Medium Log Correlation Engine Plugin ID 801025
SynopsisThe remote host is vulnerable to multiple attack vectors.
DescriptionThe remote host is using ProFTPD, a free FTP server for Unix and Linux. According to its banner, the version of ProFTPD installed on the remote host suffers from multiple format string vulnerabilities, one involving the 'ftpshut' utility and the other in mod_sql's 'SQLShowInfo' directive. Exploitation of either requires involvement on the part of a site administrator and can lead to information disclosure, denial of service, and even a compromise of the affected system.
SolutionUpgrade to version 1.3.0rc2 or higher.