Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2005:140: proftpd


Vulnerability Assessment Details

MDKSA-2005:140: proftpd

Vulnerability Assessment Summary
Check for the version of the proftpd package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2005:140 (proftpd).



Two format string vulnerabilities were discovered in ProFTPD. The first exists
when displaying a shutdown message containin the name of the current directory.
This could be exploited by a user who creates a directory containing format
specifiers and sets the directory as the current directory when the shutdown
message is being sent.

The second exists when displaying response messages to the cleint using
information retreived from a database using mod_sql. Note that mod_sql support
is not enabled by default, but the contrib source file has been patched
regardless.

The updated packages have been patched to correct these problems.



Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:140
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors


Dell PowerEdge R630 Server 3.50Ghz 8-Core 192GB 10x NEW 2TB SSD H730P Rails picture

Dell PowerEdge R630 Server 3.50Ghz 8-Core 192GB 10x NEW 2TB SSD H730P Rails

$2877.90



SRF8Z Intel Xeon Gold 6244 8-Core 3.60GHz 24.75MB 150W Processor ***New Other*** picture

SRF8Z Intel Xeon Gold 6244 8-Core 3.60GHz 24.75MB 150W Processor ***New Other***

$1479.00



Dell PowerEdge R730 Server 3.50Ghz 8-Core 32GB 9x NEW 2TB SSD HBA330 Rails picture

Dell PowerEdge R730 Server 3.50Ghz 8-Core 32GB 9x NEW 2TB SSD HBA330 Rails

$2522.35



Apple 27 iMac 3.3 GHz Intel Core i5 8GB RAM 512GB SSD Silver MXWU2LL/A Open Box picture

Apple 27 iMac 3.3 GHz Intel Core i5 8GB RAM 512GB SSD Silver MXWU2LL/A Open Box

$874.95



Intel Core i7-12700KF - Alder Lake 12-Core (8P+4E) 3.6 GHz LGA 1700 125W CPU picture

Intel Core i7-12700KF - Alder Lake 12-Core (8P+4E) 3.6 GHz LGA 1700 125W CPU

$183.49



Intel Xeon E5-2667 V2 LGA 2011 3.3GHz 8 Core 130W 25MB 8GT/s CPU Processor picture

Intel Xeon E5-2667 V2 LGA 2011 3.3GHz 8 Core 130W 25MB 8GT/s CPU Processor

$24.00



Intel - Core i9-13900K 13th Gen 24 cores 8 P-cores + 16 E-cores 36M Cache, 3 ... picture

Intel - Core i9-13900K 13th Gen 24 cores 8 P-cores + 16 E-cores 36M Cache, 3 ...

$689.99



Apple 2020 iMac 27 Inch 5K 10-CORE i9 512GB SSD 64GB RAM 5500 XT *PRO GFX* picture

Apple 2020 iMac 27 Inch 5K 10-CORE i9 512GB SSD 64GB RAM 5500 XT *PRO GFX*

$1550.00



HP Workstation Z640 2x Xeon E5-2623V4 32GB Ram Dual 256GB SSD K420 Linux GA picture

HP Workstation Z640 2x Xeon E5-2623V4 32GB Ram Dual 256GB SSD K420 Linux GA

$234.98



Dell OptiPlex 7040 Intel core I7-6700 3.4 GHz 8 GB ram No HDD/No OS picture

Dell OptiPlex 7040 Intel core I7-6700 3.4 GHz 8 GB ram No HDD/No OS

$59.99



Discussions

No Discussions have been posted on this vulnerability.