oss-sec mailing list archives
proftpd: Unauthenticated copying of files via SITE CPFR/CPTO allowed by mod_copy
From: Hanno Böck <hanno () hboeck de>
Date: Wed, 15 Apr 2015 02:39:01 +0200
This sounds serious: https://github.com/proftpd/proftpd/pull/109 http://bugs.proftpd.org/show_bug.cgi?id=4169 https://cxsecurity.com/issue/WLB-2015040075 When the module mod_copy is enabled one can copy around files on the server without any authentication. (Not sure how widespread the use of this module is.) There is no upstream release with a fix yet. cu, -- Hanno Böck http://hboeck.de/ mail/jabber: hanno () hboeck de GPG: BBB51E42
Attachment:
_bin
Description: OpenPGP digital signature
Current thread:
- proftpd: Unauthenticated copying of files via SITE CPFR/CPTO allowed by mod_copy Hanno Böck (Apr 14)