Debian Security Advisory
Debian FTP packages -- Buffer overflow in some FTP servers
- Date Reported:
- 10 Feb 1999
- Affected Packages:
- proftpd, wu-ftpd-academ
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-1999-0911.
CERT's vulnerabilities, advisories and incident notes: CA-1999-03. - More information:
-
The wu-ftpd-academ and proftpd packages distributed in Debian GNU/Linux 2.0
(hamm) are vulnerable to a buffer overflow. It is possible to gain shell
access to the machine, and we recommend upgrading these packages immediately.
Extract from the Netect report in CA-1999-03:
Intruders who are able to exploit this vulnerability can ultimately gain interactive access to the remote ftp server with root privilege.If you are using Debian GNU/Linux 2.1 (slink) you should download a new version. Note that wu-ftpd will install in a disabled state on some configurations; you can enable wu-ftpd by uncommenting the line for /usr/sbin/ftpd in /etc/inetd.conf and running
/etc/init.d/netbase reload
. The line for /usr/sbin/in.ftpd should remain disabled. - Fixed in:
-
- PROFTPD:
- Source: http://ftp.debian.org/debian/dists/stable/main/source/net/proftpd_1.2.0pre1.orig.tar.gz,
http://ftp.debian.org/debian/dists/stable/main/source/net/proftpd_1.2.0pre1-2.diff.gz,
http://ftp.debian.org/debian/dists/stable/main/source/net/proftpd_1.2.0pre1-2.dsc
- i386: http://ftp.debian.org/debian/dists/stable/main/binary-i386/net/proftpd_1.2.0pre1-2.deb
- m68k: http://ftp.debian.org/debian/dists/stable/main/binary-m68k/proftpd_1.2.0pre1-2.deb
- i386: http://ftp.debian.org/debian/dists/stable/main/binary-i386/net/proftpd_1.2.0pre1-2.deb
- WU-FTPD:
- Source: http://ftp.debian.org/debian/dists/stable/main/source/net/wu-ftpd-academ_2.4.2.16.orig.tar.gz,
http://ftp.debian.org/debian/dists/stable/main/source/net/wu-ftpd-academ_2.4.2.16-12.2.diff.gz,
http://ftp.debian.org/debian/dists/stable/main/source/net/wu-ftpd-academ_2.4.2.16-12.2.dsc
- i386: http://ftp.debian.org/debian/dists/stable/main/binary-i386/net/wu-ftpd-academ_2.4.2.16-12.2.deb
- m68k: http://ftp.debian.org/debian/dists/stable/main/binary-m68k/net/wu-ftpd-academ_2.4.2.16-12.2.deb
- i386: http://ftp.debian.org/debian/dists/stable/main/binary-i386/net/wu-ftpd-academ_2.4.2.16-12.2.deb
md5:
6fa9921e694972015d4e3d34184c4f2b proftpd_1.2.0pre1-2_i386.deb
52053f8b9f348ff1929db91951cf394f proftpd_1.2.0pre1-2_m68k.deb
b851adb345917a6f92e8b03f8cc97ff2 wu-ftpd-academ_2.4.2.16-12.2_i386.deb
9302526c8c6368f87e805e943ce66875 wu-ftpd-academ_2.4.2.16-12.2_m68k.deb