看板FB_security
标 题remotely exploitable vulnerability in lukemftpd / tnftpd
发信站NCTU CSIE FreeBSD Server (Wed Aug 18 02:36:16 2004)
转信站ptt!FreeBSD.csie.NCTU!not-for-mail
Hi Everyone,
http://vuxml.freebsd.org/c4b025bb-f05d-11d8-9837-000c41e2cdad.html
A critical vulnerability was found in lukemftpd, which shipped with some
FreeBSD versions (4.7 and later). However, with the exception of
FreeBSD 4.7, lukemftpd was not built and installed by default. So,
unless you are running FreeBSD 4.7-RELEASE or specified WANT_LUKEMFTP
when building FreeBSD from source, you should not have lukemftpd
installed.
Even in FreeBSD 4.7, lukemftpd was installed but not enabled.
More details will be available in a FreeBSD advisory to follow.
Cheers,
--
Jacques Vidrine /
[email protected] /
[email protected] /
[email protected]
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"