Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Debian Local Security Checks --> Category: infos

[DSA1217] DSA-1217-1 linux-ftpd Vulnerability Scan


Vulnerability Scan Summary
DSA-1217-1 linux-ftpd

Detailed Explanation for this Vulnerability Test

Paul Szabo discovered that the netkit ftp server switches the user id too
late, which may lead to the bypass of access restrictions when running
on NFS. This update also adds return value checks to setuid() calls, which
may fail in some PAM configurations.
For the stable distribution (sarge) this problem has been fixed in
version 0.17-20sarge2.
For the upcoming stable distribution (etch) this problem has been
fixed in version 0.17-22.
For the unstable distribution (sid) this problem has been fixed in
version 0.17-22.
We recommend that you upgrade your ftpd package.


Solution : http://www.debian.org/security/2006/dsa-1217
Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.