OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Kris Kennaway (krisOBSECURITY.ORG)
Date: Fri Feb 02 2001 - 17:04:31 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Fri, Feb 02, 2001 at 08:03:09PM +0100, Przemyslaw Frasunek wrote:

    > BTW. Old BSD derived ftpd is also used in opieftpd and SSLftpd. Both are
    > vulnerable to this attack.

    In case anyone is wondering how old is old:

    ----------------------------
    revision 1.5
    date: 1996/11/20 22:12:50; author: pst; state: Exp; lines: +9 -5
    Truncate argument list to avoid buffer overflows.

    Cannidate for: 2.1 and 2.2
    ----------------------------

    Kris

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.4 (FreeBSD)
    Comment: For info see http://www.gnupg.org

    iD8DBQE6ezz/Wry0BWjoQKURAjTdAKCfbmY6b/zSkBvv4iQjTwCfaCpbrgCfUNDE
    bVIk1wFhfWG4p9uCwGHk42Q=
    =+o2F
    -----END PGP SIGNATURE-----