oss-sec mailing list archives
Re: CVE request for proftpd
From: Vincent Danen <vdanen () redhat com>
Date: Wed, 11 Feb 2009 12:16:02 -0700
* [2009-02-11 10:58:05 -0800] TJ Saunders wrote:
An SQL injection vulnerability in proftpd was reported on bugtraq yesterday that could allow a user to login to proftpd with any password if they use mysql for authentication (and, presumably, postgresql). References: http://www.securityfocus.com/archive/1/500823/30/0/threaded http://bugs.gentoo.org/show_bug.cgi?id=258450 http://bugs.proftpd.org/show_bug.cgi?id=3180 https://bugzilla.redhat.com/show_bug.cgi?id=485125This has been reported on the ProFTPD Bugzilla: http://bugs.proftpd.org/show_bug.cgi?id=3180 As discussed there, this is a duplicate of an earlier bug: http://bugs.proftpd.org/show_bug.cgi?id=3124 and has been fixed in ProFTPD 1.3.2rc3 and later.
Oh, forgot to ask. It looks like this would have been introduced in 1.3.1. Is that correct? So the affected versions would be 1.3.1 to 1.3.2rc2. Also, as I was looking at the Gentoo report, I noticed bug #3173 which likely also needs a CVE name (for the "encoding-dependent SQL injection vulnerability"). Thanks. --Vincent Danen / Red Hat Security Response Team
Current thread:
- CVE request for proftpd Vincent Danen (Feb 11)
- Re: CVE request for proftpd TJ Saunders (Feb 11)
- Re: CVE request for proftpd Vincent Danen (Feb 11)
- Re: CVE request for proftpd Vincent Danen (Feb 11)
- Re: CVE request for proftpd TJ Saunders (Feb 11)
- Re: CVE request for proftpd Vincent Danen (Feb 11)
- Re: CVE request for proftpd TJ Saunders (Feb 11)
- Re: CVE request for proftpd Steven M. Christey (Feb 12)