Bugtraq mailing list archives

Re: wu-ftpd beta 13 Upload Ownership/Permissions Bug


From: zilbauer () CTHULHU EUROPA COM (Robert Zilbauer)
Date: Fri, 20 Jun 1997 12:03:09 -0700


At 11:55 PM 6/19/97 -0500, Michael Brennen wrote:
There is a potentially serious bug in ftpd.c in wu-ftpd beta 13.  I have
no idea if it exists in previous betas.  I don't think this was a problem
in beta 11, but I've not kept any older source.  If you are not running
beta 13, check this against your source.
[...snip...]
If upload directive processing fails for the anonymous user, sites that
depend on upload directives to properly set incoming file permissions
could find their site security compromised.

Upload directives work fine in beta 12. Must be a new addition to b13.

-----
Robert C. Zilbauer, Jr.                          Europa Communications Inc
Primary: zilbauer () europa com                   Secondary: zilbauer () efn org

          "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn."



Current thread: