Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55062
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2005:140 (proftpd)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to proftpd
announced via advisory MDKSA-2005:140.

Two format string vulnerabilities were discovered in ProFTPD. The
first exists when displaying a shutdown message containin the name of
the current directory. This could be exploited by a user who creates
a directory containing format specifiers and sets the directory as the
current directory when the shutdown message is being sent.

The second exists when displaying response messages to the cleint using
information retreived from a database using mod_sql. Note that mod_sql
support is not enabled by default, but the contrib source file has been
patched regardless.

The updated packages have been patched to correct these problems.

Affected versions: 10.0, 10.1, 10.2, Corporate 3.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:140
http://secunia.com/advisories/16181

Risk factor : High

CVSS Score:
6.4

Cross-Ref: BugTraq ID: 14381
BugTraq ID: 14380
Common Vulnerability Exposure (CVE) ID: CVE-2005-2390
http://www.securityfocus.com/bid/14380
http://www.securityfocus.com/bid/14381
Debian Security Information: DSA-795 (Google Search)
http://www.debian.org/security/2005/dsa-795
http://marc.info/?l=bugtraq&m=112604373503912&w=2
http://secunia.com/advisories/16181
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.