Nessus Plugin #15175

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA338] DSA-338-1 proftpd

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-338-1 proftpd
Version:
$Revision: 1.4 $
Cve_id:
CAN-2003-0500
Bugtraq_id:
7974
Xrefs:
DSA:338
Description:

runlevel [runlevel@raregazz.org] reported that ProFTPD's PostgreSQL
authentication module is vulnerable to a SQL injection attack. This
vulnerability could be exploited by a remote, unauthenticated attacker
to execute arbitrary SQL statements, potentially exposing the
passwords of other users, or to connect to ProFTPD as an arbitrary
user without supplying the correct password.
For the stable distribution (woody) this problem has been fixed in
version 1.2.4+1.2.5rc1-5woody2.
For the unstable distribution (sid) this problem has been fixed in
version 1.2.8-8.
We recommend that you update your proftpd package.


Solution : http://www.debian.org/security/2003/dsa-338
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.