OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Memory leakage in proftpd leads to remote DoS
From: tjRAD.GEOLOGY.WASHINGTON.EDU
Date: Wed Dec 20 2000 - 13:48:06 CST


> I've tested on proftd-1.2.0rc2 and people confirmed that this bug exist in
> the latest CVS version.
>
> I had no time to look at the code so no patch is currently available.
> Developers have just been informed.
>
> +--------------------------------------------------------------------+
> | Wojciech Purczynski wpelzabsoft.pl http://www.elzabsoft.pl/~wp |
> | GSM: +48604432981 Linux Administrator SMS: wp-smselzabsoft.pl |
> +------ Public GnuPG Key: http://www.elzabsoft.pl/~wp/gpg.asc ------+

The developers of proftpd have tried to confirm this bug, using scripts to
issue the SIZE command for hundred thousands of iterations, and failed to
verify that it does indeed exist.

Versions of proftpd tested: pre10, rc1, rc2, and CVS. All failed to show
symptoms of this memory leak.

----------------------------------------------------------------------------
TJ Saunders tjrad.geology.washington.edu
System Administrator Phone: (206) 685-8266
Remote Sensing Lab Fax: (206) 685-2379
University of Washington
----------------------------------------------------------------------------