Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50776
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2003:095-1 (proftpd)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to proftpd
announced via advisory MDKSA-2003:095-1.

A vulnerability was discovered by X-Force Research at ISS in ProFTPD's
handling of ASCII translation. An attacker, by downloading a carefully
crafted file, can remotely exploit this bug to create a root shell.

The ProFTPD team encourages all users to upgrade to version 1.2.7 or
higher. The problematic code first appeared in ProFTPD 1.2.7rc1, and
the provided packages are all patched by the ProFTPD team to protect
against this vulnerability.

Update:

The previous update had a bug where the new packages would terminate
with a SIGNAL 11 when the command NLST -alL was performed in
certain cases, such as if the size of the output of the command was
greater than 1024 bytes.

These updated packages have a fix applied to prevent this crash.

Affected versions: 9.1, 9.2

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2003:095-1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0831
http://xforce.iss.net/xforce/alerts/id/154
http://bugs.proftpd.org/show_bug.cgi?id=2194

Risk factor : Critical

CVSS Score:
9.0

Cross-Ref: BugTraq ID: 8679
Common Vulnerability Exposure (CVE) ID: CVE-2003-0831
Bugtraq: 20030924 [slackware-security] ProFTPD Security Advisory (SSA:2003-259-02) (Google Search)
http://marc.info/?l=bugtraq&m=106441655617816&w=2
Bugtraq: 20031013 Remote root exploit for proftpd \n bug (Google Search)
http://marc.info/?l=bugtraq&m=106606885611269&w=2
CERT/CC vulnerability note: VU#405348
http://www.kb.cert.org/vuls/id/405348
https://www.exploit-db.com/exploits/107/
http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012072.html
ISS Security Advisory: 20030923 ProFTPD ASCII File Remote Compromise Vulnerability
http://xforce.iss.net/xforce/alerts/id/154
http://www.mandriva.com/security/advisories?name=MDKSA-2003:095
http://secunia.com/advisories/9829
XForce ISS Database: proftpd-ascii-xfer-newline-bo(12200)
https://exchange.xforce.ibmcloud.com/vulnerabilities/12200
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.