Bugtraq mailing list archives

Re: Memory leakage in proftpd leads to remote DoS


From: "Rodrigo Barbosa (aka morcego)" <rodrigob () CONECTIVA COM BR>
Date: Fri, 22 Dec 2000 18:07:03 -0200

On Fri, Dec 22, 2000 at 01:53:01PM +0100, Wojciech Purczynski wrote:
The developers of proftpd have tried to confirm this bug, using scripts to
issue the SIZE command for hundred thousands of iterations, and failed to
verify that it does indeed exist.

Versions of proftpd tested: pre10, rc1, rc2, and CVS.  All failed to show
symptoms of this memory leak.

I've investigated the problem a little bit more and it seems that this
memory leakage really _exist_ but only if proftpd runs in INETD mode.

If proftpd works as standalone daemon it works fine and does not consume
system memory.

I'll not repeat here all we said and discussed before. If anyone want
any further information on this, please refer to
http://bugs.proftpd.net/show_bug.cgi?id=408

The official position is: this bug does not exist.
No one every showed us any way we could reproduce it. All reports only
showed lack of compreension and misguidance.

Tkx

-- 
 Rodrigo Barbosa (morcego)  - rodrigob at conectiva.com.br
 Conectiva R&D Team         - http://distro.conectiva.com.br
 "Quis custodiet custodes?" - http://www.conectiva.com

Attachment: _bin
Description:


Current thread: