LWN.net Logo

GProFTPD: gprostats format string vulnerability

Package(s):gproftpd CVE #(s):
Created:February 18, 2005 Updated:February 23, 2005
Description: Tavis Ormandy of the Gentoo Linux Security Audit Team has identified a format string vulnerability in the gprostats utility. An attacker could exploit the vulnerability by performing a specially crafted FTP transfer, the resulting ProFTPD transfer log could potentially trigger the execution of arbitrary code when parsed by GProFTPD.
Alerts:
Gentoo 200502-26 2005-02-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds