Nessus Plugin #15175
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[DSA338] DSA-338-1 proftpd
- Family:
- Debian Local Security Checks
- Category:
- infos
- Copyright:
- This script is (C) 2004 Michel Arboi
- Summary:
- DSA-338-1 proftpd
- Version:
- $Revision: 1.4 $
- Cve_id:
- CAN-2003-0500
- Bugtraq_id:
- 7974
- Xrefs:
- DSA:338
- Description:
runlevel [runlevel@raregazz.org] reported that ProFTPD's PostgreSQL
authentication module is vulnerable to a SQL injection attack. This
vulnerability could be exploited by a remote, unauthenticated attacker
to execute arbitrary SQL statements, potentially exposing the
passwords of other users, or to connect to ProFTPD as an arbitrary
user without supplying the correct password.
For the stable distribution (woody) this problem has been fixed in
version 1.2.4+1.2.5rc1-5woody2.
For the unstable distribution (sid) this problem has been fixed in
version 1.2.8-8.
We recommend that you update your proftpd package.
Solution : http://www.debian.org/security/2003/dsa-338
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.