| Description: | The remote host is missing an update to proftpd announced via advisory MDKSA-2006:217.
As disclosed by an exploit (vd_proftpd.pm) and a related vendor bugfix, a Denial of Service (DoS) vulnerability exists in the FTP server ProFTPD, up to and including version 1.3.0. The flaw is due to both a potential bus error and a definitive buffer overflow in the code which determines the FTP command buffer size limit. The vulnerability can be exploited only if the CommandBufferSize directive is explicitly used in the server configuration, which is not the case in the default configuration of ProFTPD.
Packages have been patched to correct these issues.
Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0
Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2006:217
Risk factor : Critical |