remote code execution in ProFTPD

Bug #73603 reported by magilus
258
Affects Status Importance Assigned to Milestone
Dapper Backports
Invalid
Critical
Unassigned
Edgy Backports
Invalid
Undecided
Unassigned
linux-ftpd (Ubuntu)
Invalid
Undecided
Unassigned
proftpd-dfsg (Debian)
Fix Released
Unknown
proftpd-dfsg (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Undecided
Unassigned
Edgy
Fix Released
Undecided
Unassigned

Bug Description

On 6 November 2006, Evgeny Legerov <email address hidden> posted to BUGTRAQ[1],
announcing his commercial VulnDisco Pack for Metasploit 2.7[2]. One of the
included exploits, vd_proftpd.pm, takes advantage of an off-by-one string
manipulation flaw in ProFTPD's sreplace() function to allow a remote
attacker to execute arbitrary code.

[...]

Full description and patch is available at

http://bugs.proftpd.org/show_bug.cgi?id=2858

CVE References

Revision history for this message
Kees Cook (kees) wrote :

This package is in universe, so if someone can prepare a tested debdiff for the released Ubuntu versions, I'd be happy to upload it into the Ubuntu security repository.

Changed in proftpd:
status: Unconfirmed → Confirmed
Kees Cook (kees)
Changed in edgy-backports:
status: Unconfirmed → Rejected
Revision history for this message
John Dong (jdong) wrote :

   proftpd | 1.3.0-9~dapper1 | dapper-backports/universe | source, i386

I'm assuming dapper-backports 1.3.0-9 is affected?

Changed in dapper-backports:
importance: Undecided → Critical
Changed in proftpd-dfsg:
status: Unconfirmed → Fix Released
Kees Cook (kees)
Changed in dapper-backports:
status: Unconfirmed → Rejected
Revision history for this message
Brandon Holtsclaw (imbrandon) wrote :

no , jdong, no backports , this is getting out in -security, was a mis-file on the bug , thanks for the watchfull eye

Changed in proftpd-dfsg:
status: Fix Released → Fix Committed
Kees Cook (kees)
Changed in proftpd:
status: Unconfirmed → Rejected
Changed in proftpd-dfsg:
status: Unknown → Fix Released
Kees Cook (kees)
Changed in proftpd-dfsg:
status: Unconfirmed → Fix Released
status: Fix Committed → Fix Released
Revision history for this message
Daniel T Chen (crimsun) wrote :

This is already fixed in the latest Feisty merge.

Changed in proftpd-dfsg:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.