ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Adrian Minta
Any debian reaction on this ? http://seclists.org/fulldisclosure/2010/Nov/49 -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/4ce15cb4.5070...@gmail.com

Re: ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Adam D. Barratt
On Mon, November 15, 2010 16:15, Adrian Minta wrote: Any debian reaction on this ? http://seclists.org/fulldisclosure/2010/Nov/49 This is CVE-2010-4221. It's been fixed in unstable and testing since before the post you reference was made, and doesn't affect stable. Regards, Adam -- To

Re: ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Sven Hoexter
On Mon, Nov 15, 2010 at 06:15:48PM +0200, Adrian Minta wrote: Any debian reaction on this ? http://seclists.org/fulldisclosure/2010/Nov/49 It doesn't effect the version shipped with Lenny and is fixed in testing and unstable. http://bugs.proftpd.org/show_bug.cgi?id=3521

Re: ProFTPD IAC Remote Root Exploit

2010-11-15 Thread Adrian Minta
On 11/15/10 18:41, Sven Hoexter wrote: On Mon, Nov 15, 2010 at 06:15:48PM +0200, Adrian Minta wrote: Any debian reaction on this ? http://seclists.org/fulldisclosure/2010/Nov/49 It doesn't effect the version shipped with Lenny and is fixed in testing and unstable.