Date: Wed, 15 Apr 2015 02:39:01 +0200 From: Hanno Böck <hanno@...eck.de> To: oss-security <oss-security@...ts.openwall.com> Subject: proftpd: Unauthenticated copying of files via SITE CPFR/CPTO allowed by mod_copy This sounds serious: https://github.com/proftpd/proftpd/pull/109 http://bugs.proftpd.org/show_bug.cgi?id=4169 https://cxsecurity.com/issue/WLB-2015040075 When the module mod_copy is enabled one can copy around files on the server without any authentication. (Not sure how widespread the use of this module is.) There is no upstream release with a fix yet. cu, -- Hanno Böck http://hboeck.de/ mail/jabber: hanno@...eck.de GPG: BBB51E42 [ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ