|
|
| |
|
| |
proftpd: code execution
| Package(s): | proftpd |
CVE #(s): | CVE-2010-4652
|
| Created: | January 28, 2011 |
Updated: | March 15, 2011 |
| Description: |
From the Red Hat bugzilla entry:
A heap-based buffer overflow flaw was found in the way ProFTPD FTP server
prepared SQL queries for certain usernames, when the mod_sql module was
enabled. A remote, unauthenticated attacker could use this flaw to
cause proftpd daemon to crash or, potentially, to execute arbitrary
code with the privileges of the user running 'proftpd' via a specially-crafted
username, provided in the authentication dialog.
|
| Alerts: |
|
( Log in to post comments)
|
|
|