Mandrake Linux Security Advisory : proftpd (MDKSA-2001:021)

High Nessus Plugin ID 61895


The remote Mandrake Linux host is missing a security update.


The ProFTPD FTP server has problems with memory leaking that could be used in a DoS attack, as reported by Wojciech Purczynski. A memory leak will happen every time a SIZE command was given provided that the scoreboard file is not writable, which is not the case in a default Linux-Mandrake installation. A similar problem also existed with the USER command where every time it was given the server would use more memory. Additionally, some format string vulnerabilities were reported by Przemyslaw Frasunek which have also been fixed.


Update the affected proftpd package.

Plugin Details

Severity: High

ID: 61895

File Name: mandrake_MDKSA-2001-021.nasl

Version: $Revision: 1.4 $

Type: local

Published: 2012/09/06

Modified: 2018/02/09

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:proftpd, cpe:/o:mandrakesoft:mandrake_linux:7.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2001/02/08

Reference Information

CVE: CVE-2001-0136, CVE-2001-0318

MDKSA: 2001:021