Bugtraq mailing list archives

Re: Fw: Remote bufferoverflow exploit for ftpd from AIX 4.3.2


From: wfp5p () CTHULHU ITC VIRGINIA EDU (Bill Pemberton)
Date: Wed, 29 Sep 1999 15:49:12 -0400


W.H.J.Pinckaers writes:

sq01 () Yorku Ca <sq01 () Yorku Ca> Wrote

Hi,

Short of disabling ftpd completely, is there a work-around that will not
affect our users ?



At this time: NO, but please make sure you are vulnerable first, we
did discover that this bug is very specific for AIX 4.3.2. (Most other
AIX versions aren't vulnerable to this particular bug)


Actually, IBM does have an efix for this at:

ftp://aix.software.ibm.com/aix/efixes/security/ftpd.tar.Z


--
Bill Pemberton                                 wfp5p () virginia edu
ITC/Unix Systems                               flash () virginia edu
University of Virginia



Current thread: