漏洞信息详情
ProFTPD 1.2远程缓冲区溢出漏洞
- CNNVD编号:CNNVD-199908-055
- 危害等级: 超危
- CVE编号:
CVE-1999-0911
- 漏洞类型:
边界条件错误
- 发布时间:
1999-08-27
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
proftpd_project - 漏洞来源:
acidrain※ acidrain… -
漏洞简介
ProFTPD是一种使用比较广泛的FTP服务器程序。
ProFTPD 1.2版实现上存在缓冲区溢出漏洞,远程攻击者可能通过溢出攻击在主机上以root用户的权限执行任意指令。
ProFTPD 1.2pre1、1.2pre3、1.2pre3在src/log.c的log_xfer()函数中,由于snprintf()调用使用不正确,存在远程可利用的缓冲区溢出漏洞。1.2pre4版本存在一个mkdir溢出漏洞,目录名长度超过255个字节就会导致溢出。
漏洞公告
厂商补丁:
Debian
——
Debian已经为此发布了一个安全公告(1999-11-11.1)以及相应补丁:
1999-11-11.1:buffer overflows in proftpd
链接:http://www.debian.org/security/1999/1999-11” target=”_blank”>
http://www.debian.org/security/1999/1999-11
补丁下载:
Source:
http://security.debian.org/dists/slink/updates/source/proftpd_1.2.0pre9-4.diff.gz” target=”_blank”>
http://security.debian.org/dists/slink/updates/source/proftpd_1.2.0pre9-4.diff.gz
http://security.debian.org/dists/slink/updates/source/proftpd_1.2.0pre9-4.dsc” target=”_blank”>
http://security.debian.org/dists/slink/updates/source/proftpd_1.2.0pre9-4.dsc
http://security.debian.org/dists/slink/updates/source/proftpd_1.2.0pre9.orig.tar.gz” target=”_blank”>
http://security.debian.org/dists/slink/updates/source/proftpd_1.2.0pre9.orig.tar.gz
Alpha:
http://security.debian.org/dists/slink/updates/binary-alpha/proftpd_1.2.0pre9-4_alpha.deb” target=”_blank”>
http://security.debian.org/dists/slink/updates/binary-alpha/proftpd_1.2.0pre9-4_alpha.deb
i386:
http://security.debian.org/dists/slink/updates/binary-i386/proftpd_1.2.0pre9-4_i386.deb” target=”_blank”>
http://security.debian.org/dists/slink/updates/binary-i386/proftpd_1.2.0pre9-4_i386.deb
m68k:
http://security.debian.org/dists/slink/updates/binary-m68k/proftpd_1.2.0pre9-4_m68k.deb” target=”_blank”>
http://security.debian.org/dists/slink/updates/binary-m68k/proftpd_1.2.0pre9-4_m68k.deb
Sparc:
http://security.debian.org/dists/slink/updates/binary-sparc/proftpd_1.2.0pre9-4_sparc.deb” target=”_blank”>
http://security.debian.org/dists/slink/updates/binary-sparc/proftpd_1.2.0pre9-4_sparc.deb
S.u.S.E.
——–
S.u.S.E.已经为此发布了一个安全公告(SuSE-018)以及相应补丁:
SuSE-018:Security hole in ProFTPD
补丁下载:
http://www.suse.de/patches/index.html” target=”_blank”>
http://www.suse.de/patches/index.html
参考网址
来源: BID
名称: 612
链接:http://www.securityfocus.com/bid/612
来源: DEBIAN
名称: 19990210
链接:http://www.debian.org/security/1999/19990210
来源:NSFOCUS
名称:3488
链接:http://www.nsfocus.net/vulndb/3488