*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

Proftpd version 1.3.1-6ubuntu1 exploit:

The variable substitution feature in the version of ProFTPD running on
the remote host can be abused to conduct a SQL injection attack. For
example, a remote attacker can bypass authentication using a specially
crafted username containing a percent sign character ('%'), a single
quote, and SQL code.

http://www.securityfocus.com/archive/1/500823/30/0/threaded

http://bugs.proftpd.org/show_bug.cgi?id=3124http://bugs.proftpd.org/show_bug.cgi?id=3180

http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2rc3

http://www.proftpd.org/docs/NEWS-1.3.2rc3http://comments.gmane.org/gmane.comp.security.oss.general/1489

Solution: Upgrade to ProFTPD 1.3.2rc3 or later.

Could this be fixed in Ubuntu 8.04.4 LTS?

** Affects: proftpd-dfsg (Ubuntu)
     Importance: Undecided
         Status: New

-- 
Ubuntu 8.04.4 LTS - Proftpd SQL exploit
https://bugs.launchpad.net/bugs/997113
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to