oss-sec mailing list archives

Re: CVE id request: ftpd


From: Josh Bressers <bressers () redhat com>
Date: Tue, 30 Sep 2008 14:34:07 -0400 (EDT)


----- "Steven M. Christey" <coley () linus mitre org> wrote:

CVE-2008-4247 is for *BSD's ftpd; CVE-2008-4242 is for ProFTPD.


I'm pretty sure this also affects at least wu-ftpd, but looking into what
else is on my list of things to do.  From my quick investigation, the file
in question (ftpcmd.y) is in lots of other ftp daemons, and the code is
eerily similar.

-- 
    JB


Current thread: