OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Wu-ftpd FTP server contains remotely exploitable off-by-one bug

From: Mike Tancsa (mikesentex.net)
Date: Thu Jul 31 2003 - 13:52:56 CDT


At 02:40 PM 31/07/2003 -0400, polytarpcyberspace.org wrote:

>Buffer overflows which work on Linux do not work on FreeBSD.

You need to qualify that statement. Yes, there are some that will not be
relevant and the exact same exploit code will not work. But "Buffer
overflows which work on Linux do not work on FreeBSD" is dangerously
misleading.... In the case of wu-ftpd there have been several issues in the
past that affected both FreeBSD and Linux. Same bug, different exploit
code, both vulnerable. That being said, I havent had a chance to review
this one so I dont know.

         ---Mike

_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"