*** This bug is a security vulnerability ***
You have been subscribed to a public security bug by Marc Deslauriers
(mdeslaur):
Proftpd version 1.3.1-6ubuntu1 exploit:
The variable substitution feature in the version of ProFTPD running on
the remote host can be abused to conduct a SQL injection attack. For
example, a remote attacker can bypass authentication using a specially
crafted username containing a percent sign character ('%'), a single
quote, and SQL code.
http://www.securityfocus.com/archive/1/500823/30/0/threaded
http://bugs.proftpd.org/show_bug.cgi?id=3124
http://bugs.proftpd.org/show_bug.cgi?id=3180
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2rc3
http://www.proftpd.org/docs/NEWS-1.3.2rc3
http://comments.gmane.org/gmane.comp.security.oss.general/1489
Solution: Upgrade to ProFTPD 1.3.2rc3 or later.
Could this be fixed in Ubuntu 8.04.4 LTS?
** Affects: proftpd-dfsg (Ubuntu)
Importance: Undecided
Status: New
--
Ubuntu 8.04.4 LTS - Proftpd SQL exploit
https://bugs.launchpad.net/bugs/997113
You received this bug notification because you are a member of Ubuntu Bugs,
which is subscribed to the bug report.
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs