GLSA-200502-26 : GProFTPD: gprostats format string vulnerability
High Nessus Plugin ID 17145
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200502-26 (GProFTPD: gprostats format string vulnerability)
Tavis Ormandy of the Gentoo Linux Security Audit Team has identified a format string vulnerability in the gprostats utility.
An attacker could exploit the vulnerability by performing a specially crafted FTP transfer, the resulting ProFTPD transfer log could potentially trigger the execution of arbitrary code when parsed by GProFTPD.
There is no known workaround at this time.
SolutionAll GProFTPD users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-ftp/gproftpd-8.1.9'