Full Disclosure mailing list archives

Fwd: solution to wu-ftpd + tar program execution


From: "smith jerome" <securebox () hotmail com>
Date: Mon, 08 Sep 2003 11:59:34 +0300

This has been known for a long time:
http://www.security-express.com/archives/bugtraq/1999-q4/0405.html

There is an easy solution to this which don't cut functionality:
in ftpconversions place " -- " before "%s" in every line which has tar
(probably on all lines is a good idea).
" -- " terminates the arguments passed to tar, so programs can't be
injected.

linux distributions were notified about the solution, debian released an
advisory at:
http://www.debian.org/security/2003/dsa-377

georgi

_________________________________________________________________
Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: