LWN.net Logo

Slackware security update to proftpd

Slackware security update to proftpd

Posted Sep 24, 2003 21:58 UTC (Wed) by dwalters (subscriber, #4207)
Parent article: Slackware security update to proftpd

Can one assume that for an attacker to be able to download a "suitably crafted file", they must have been able to upload it to the server first?

I'd be interested to know if this is remotely exploitable on a system that has FTP uploads completely disabled, and is not accessible by any other means except via SSH (recently patched) by a trusted person (me).


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds