oss-sec mailing list archives

Re: vsftpd CVE-2007-5962 (Red Hat / Fedora specific)


From: "Steven M. Christey" <coley () linus mitre org>
Date: Thu, 22 May 2008 02:01:05 -0400 (EDT)


On Wed, 21 May 2008, Josh Bressers wrote:

The leak is CVE-2007-5962.  deny_hosts not working did not get a CVE id.

Should it?  If an admin configures deny_hosts in some fashion that vsftpd
doesn't implement correctly, that might be worthy of a CVE.

- Steve


Current thread: