OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Memory leakage in proftpd leads to remote DoS
From: Rodrigo Barbosa (aka morcego) (rodrigobCONECTIVA.COM.BR)
Date: Fri Dec 22 2000 - 14:07:03 CST


On Fri, Dec 22, 2000 at 01:53:01PM +0100, Wojciech Purczynski wrote:
> > The developers of proftpd have tried to confirm this bug, using scripts to
> > issue the SIZE command for hundred thousands of iterations, and failed to
> > verify that it does indeed exist.
> >
> > Versions of proftpd tested: pre10, rc1, rc2, and CVS. All failed to show
> > symptoms of this memory leak.
>
> I've investigated the problem a little bit more and it seems that this
> memory leakage really _exist_ but only if proftpd runs in INETD mode.
>
> If proftpd works as standalone daemon it works fine and does not consume
> system memory.

I'll not repeat here all we said and discussed before. If anyone want
any further information on this, please refer to
http://bugs.proftpd.net/show_bug.cgi?id=408

The official position is: this bug does not exist.
No one every showed us any way we could reproduce it. All reports only
showed lack of compreension and misguidance.

Tkx

-- 
 Rodrigo Barbosa (morcego)  - rodrigob at conectiva.com.br
 Conectiva R&D Team         - http://distro.conectiva.com.br
 "Quis custodiet custodes?" - http://www.conectiva.com


  • application/pgp-signature attachment: stored