GProFTPD: gprostats format string vulnerability
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200502-26 / GProFTPD |
| Release Date |
February 18, 2005 |
| Latest Revision |
May 22, 2006: 02 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-ftp/gproftpd |
<
8.1.9 |
>=
8.1.9 |
All supported architectures
|
Related bugreports:
#81894
Synopsis
gprostats, distributed with GProFTPD, is vulnerable to a format string
vulnerability, potentially leading to the execution of arbitrary code.
2.
Impact Information
Background
GProFTPD is a GTK+ administration tool for the ProFTPD server. GProFTPD
is distributed with gprostats, a utility to parse ProFTPD transfer
logs.
Description
Tavis Ormandy of the Gentoo Linux Security Audit Team has identified a
format string vulnerability in the gprostats utility.
Impact
An attacker could exploit the vulnerability by performing a specially
crafted FTP transfer, the resulting ProFTPD transfer log could
potentially trigger the execution of arbitrary code when parsed by
GProFTPD.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All GProFTPD users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-ftp/gproftpd-8.1.9"
|
4.
References
|