OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: remotely exploitable vulnerability in lukemftpd / tnftpd

From: Jacques A. Vidrine (nectarFreeBSD.org)
Date: Tue Aug 17 2004 - 16:16:27 CDT


On Tue, Aug 17, 2004 at 05:14:16PM -0400, Chuck Swiger wrote:
> Jacques A. Vidrine wrote:
> [ ... ]
> >Even in FreeBSD 4.7, lukemftpd was installed but not enabled.
> >
> >More details will be available in a FreeBSD advisory to follow.
>
> Hi, Jacques--
>
> Is this related to NetBSD Security Advisory 2004-009, at:
> ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-009.txt.asc?

Yes, same issue.

> More importantly, is FreeBSD's stock ftpd also affected, or just lukemftpd?

Just lukemftpd. Przemyslaw's advisory has more details.
http://lists.netsys.com/pipermail/full-disclosure/2004-August/025418.html

Cheers,
--
Jacques Vidrine / nectarcelabo.org / jvidrineverio.net / nectarfreebsd.org
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"