|
Family: Debian Local Security Checks --> Category: infos
[DSA338] DSA-338-1 proftpd Vulnerability Scan
Vulnerability Scan Summary DSA-338-1 proftpd
Detailed Explanation for this Vulnerability Test
runlevel [runlevel@raregazz.org] reported that ProFTPD's PostgreSQL
authentication module is vulnerable to a SQL injection attack. This
vulnerability could be exploited by a remote, unauthenticated attacker
to execute arbitrary SQL statements, potentially exposing the
passwords of other users, or to connect to ProFTPD as an arbitrary
user without supplying the correct password.
For the stable distribution (woody) this problem has been fixed in
version 1.2.4+1.2.5rc1-5woody2.
For the unstable distribution (sid) this problem has been fixed in
version 1.2.8-8.
We recommend that you update your proftpd package.
Solution : http://www.debian.org/security/2003/dsa-338
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|