VID |
16143 |
Severity |
40 |
Port |
21, ... |
Protocol |
TCP |
Class |
FTP |
Detailed Description |
According to its banner, the version of ProFTPD installed on the remote host is earlier than 1.3.3d. Such versions are reportedly affected by a heap based buffer overflow vulnerability in the function 'sql_prepare_where()' in the file 'contrib/mod_sql.c'. An unauthenticated remote attacker may be able to exploit this in combination with an earlier SQL injection vulnerability (CVE-2009-0542) to execute arbitrary code with root privileges.
* Note: This check solely relied on the banner of the remote FTP server to assess this vulnerability, so this might be a false positive.
* References: http://phrack.org/issues.html?issue=67&id=7#article http://bugs.proftpd.org/show_bug.cgi?id=3536 http://www.proftpd.org/docs/RELEASE_NOTES-1.3.3d
* Platforms Affected: ProFTPD Project, ProFTPD versions prior to 1.3.3d Linux Any version Unix Any version |
Recommendation |
Upgrade to the latest version of ProFTPD (1.3.3d or later), available from the ProFTPD Web site at http://www.proftpd.org/ |
Related URL |
CVE-2010-4652 (CVE) |
Related URL |
44933 (SecurityFocus) |
Related URL |
(ISS) |
|