proftpd security vulerability??? Where can I find more info?

Status
Not open for further replies.

BianchiDude

Well-Known Member
PartnerNOC
Jul 2, 2005
617
0
166
cpanelnick said:
We were not able to confirm it on more then one machine so far. At this point, its just an advisory. We feel its better to be proactive instead of reactive in the event it does turn out to be a major problem. Given that pure-ftpd has a better security history then proftpd, we feel this is the wisest course at this time.
I dont understand this, how could it only affect 1 machine, the same proftpd software would be on everyones software, have you tested it on more than one machine? Do you mean it only affects 1 distro of linux (or freeBSD) is so which distro?
 

BianchiDude

Well-Known Member
PartnerNOC
Jul 2, 2005
617
0
166
BianchiDude said:
Can you give us a little more info? At least tell us if its a buffer overflow or not.
Also, can it be performed remotely or do you need a user account? Nick, when you got root did you do it remotely or with an underprivledged user account? Please let us know this basic information without giving specfic details on how you got root so that we may know how serious of a bug this is. I have a lot of dedicated server customers and will take some time to get them all to change as I dont have root to all of their servers.
 

Vatoloco

Well-Known Member
Jun 21, 2004
99
0
166
BianchiDude said:
Also, can it be performed remotely or do you need a user account? Nick, when you got root did you do it remotely or with an underprivledged user account? Please let us know this basic information without giving specfic details on how you got root so that we may know how serious of a bug this is.
I would like to know this as well. If it takes having at least a valid user account before being able to get root, I'm not going to be as worried about this.
 

chirpy

Well-Known Member
Verifed Vendor
Jun 15, 2002
13,437
33
473
Go on, have a guess
BianchiDude said:
Can you give us a little more info? At least tell us if its a buffer overflow or not.
cPanel have already told you that they are not going to release any information about the vulnerability and will provide details to proftpd when they have specific details. For now, you have the workaround fix for switching to pure-ftpd.
 
Status
Not open for further replies.