Search:     Advanced search
server monitoring

proftpd 1.2.0rc2 format string vuln

Article ID: 11407
Last updated: 27 Jan, 2009
Views: 405
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

proftpd 1.2.0rc2 format string vuln

This script is Copyright (C) 2003 Renaud Deraison

FamilyFTP
Plugin ID11407
Bugtraq ID6781
CVE IDCVE-2001-0318

Description:

The remote ProFTPd server is as old or older than 1.2.0rc2

There is a very hard to exploit format string vulnerability in
this version, which may allow an attacker to execute arbitrary
code on this host.

The vulnerability is believed to be nearly impossible to exploit
though

Solution : Upgrade to a newer version
Risk factor : Medium
This article was:   Helpful | Not Helpful
Prev   Next
Fake FTP server accepts a bad sequence of commands     Passwordless Zaurus FTP server