remotely exploitable vulnerability in lukemftpd / tnftpd

From: Jacques A. Vidrine (nectar_at_FreeBSD.org)
Date: 08/17/04

  • Next message: Chuck Swiger: "Re: remotely exploitable vulnerability in lukemftpd / tnftpd"
    Date: Tue, 17 Aug 2004 13:47:25 -0500
    To: freebsd-security@freebsd.org
    
    

    Hi Everyone,

    http://vuxml.freebsd.org/c4b025bb-f05d-11d8-9837-000c41e2cdad.html

    A critical vulnerability was found in lukemftpd, which shipped with some
    FreeBSD versions (4.7 and later). However, with the exception of
    FreeBSD 4.7, lukemftpd was not built and installed by default. So,
    unless you are running FreeBSD 4.7-RELEASE or specified WANT_LUKEMFTP
    when building FreeBSD from source, you should not have lukemftpd
    installed.

    Even in FreeBSD 4.7, lukemftpd was installed but not enabled.

    More details will be available in a FreeBSD advisory to follow.

    Cheers,

    -- 
    Jacques Vidrine / nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Chuck Swiger: "Re: remotely exploitable vulnerability in lukemftpd / tnftpd"

    Relevant Pages

    • Re: 7-STABLE regression that breaks lang/drscheme is src/contrib/gcc/gthr-posix.h 1.1.1.8.2.
      ... built from ports/lang/drscheme (or actually manually ... problem is probably the drscheme FreeBSD configuration that has ... now that FreeBSD has changed slightly. ... causing an existing binary to run or not, ...
      (freebsd-stable)
    • Re: Ports and packages
      ... I don't know that you speak for the entire FreeBSD community, ... megs, it and the JDK together built in a matter of hours, I don't ... linux* do not necessairily hold on FreeBSD, in large part for reasons ... Please do move back to linux or wherever it is ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Another attempt [Re: Groff is not working in the latest code]
      ... That code is configured by the pristine `contrib/groff/configure' ... replaced with the FreeBSD hard versions that had been delivered ... `man man` works for me on 7.0-RELEASE with groff built from RELENG_7 src. ...
      (freebsd-stable)
    • user level
      ... I assembled my first computer in March of 2005. ... I have built one tower and built a computer for ... I have tried several times to install and run FreeBSD and ran ...
      (freebsd-questions)
    • Re: quick question regarding /usr/obj
      ... FreeBSD shadow.meridiantelekoms.com ... Now, my question is, is the custom kernel I built ... each time you update ports some of these files become ...
      (freebsd-questions)