Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.57664
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2006:217-1 (proftpd)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to proftpd
announced via advisory MDKSA-2006:217-1.

A stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0
and earlier, allows remote attackers to cause a denial of service, as
demonstrated by vd_proftpd.pm, a ProFTPD remote exploit.
(CVE-2006-5815)

Buffer overflow in the tls_x509_name_oneline function in the mod_tls
module, as used in ProFTPD 1.3.0a and earlier, and possibly other
products, allows remote attackers to execute arbitrary code via a large
data length argument, a different vulnerability than CVE-2006-5815.
(CVE-2006-6170)

ProFTPD 1.3.0a and earlier does not properly set the buffer size limit
when CommandBufferSize is specified in the configuration file, which
leads to an off-by-two buffer underflow. NOTE: in November 2006, the
role of CommandBufferSize was originally associated with CVE-2006-5815,
but this was an error stemming from an initial vague disclosure. NOTE:
ProFTPD developers dispute this issue, saying that the relevant memory
location is overwritten by assignment before further use within the
affected function, so this is not a vulnerability. (CVE-2006-6171)

Packages have been patched to correct these issues.

Update:

The previous update incorrectly linked the vd_proftd.pm issue with the
CommandBufferSize issue. These are two distinct issues and the previous
update only addressed CommandBufferSize (CVE-2006-6171), and the
mod_tls issue (CVE-2006-6170).

Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2006:217-1

Risk factor : Critical

CVSS Score:
10.0

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2006-5815
BugTraq ID: 20992
http://www.securityfocus.com/bid/20992
Bugtraq: 20061127 CVE-2006-5815: remote code execution in ProFTPD (Google Search)
http://www.securityfocus.com/archive/1/452760/100/200/threaded
Debian Security Information: DSA-1222 (Google Search)
http://www.debian.org/security/2006/dsa-1222
http://www.gentoo.org/security/en/glsa/glsa-200611-26.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:217
http://www.mandriva.com/security/advisories?name=MDKSA-2006:217-1
http://gleg.net/vulndisco_meta.shtml
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.035-proftpd.html
http://securitytracker.com/id?1017167
http://secunia.com/advisories/22803
http://secunia.com/advisories/22821
http://secunia.com/advisories/23000
http://secunia.com/advisories/23069
http://secunia.com/advisories/23125
http://secunia.com/advisories/23174
http://secunia.com/advisories/23179
http://secunia.com/advisories/23184
http://secunia.com/advisories/23207
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.502491
http://www.trustix.org/errata/2006/0066/
http://www.trustix.org/errata/2006/0070
http://www.vupen.com/english/advisories/2006/4451
XForce ISS Database: proftpd-code-execution(30147)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30147
Common Vulnerability Exposure (CVE) ID: CVE-2006-6170
BugTraq ID: 21326
http://www.securityfocus.com/bid/21326
Bugtraq: 20061121 Re: [ MDKSA-2006:217 ] - Updated proftpd packages fix vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/452228/100/100/threaded
Bugtraq: 20061128 ProFTPD mod_tls pre-authentication buffer overflow (Google Search)
http://www.securityfocus.com/archive/1/452872/100/0/threaded
Bugtraq: 20061129 Re: ProFTPD mod_tls pre-authentication buffer overflow (Google Search)
http://www.securityfocus.com/archive/1/452993/100/100/threaded
http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050935.html
http://elegerov.blogspot.com/2006/10/do-you-remember-2-years-old-overflow.html
http://secunia.com/advisories/23141
http://www.trustix.org/errata/2006/0066
http://www.vupen.com/english/advisories/2006/4745
XForce ISS Database: proftpd-modtls-bo(30554)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30554
Common Vulnerability Exposure (CVE) ID: CVE-2006-6171
Debian Security Information: DSA-1218 (Google Search)
http://www.debian.org/security/2006/dsa-1218
http://proftp.cvs.sourceforge.net/proftp/proftpd/src/main.c?r1=1.292&r2=1.293&sortby=date
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.035.html
http://secunia.com/advisories/23329
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.