Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 11 Mar 2016 22:22:40 +0100
From: Moritz Mühlenhoff <jmm@...til.org>
To: oss-security@...ts.openwall.com
Cc: cve-assign@...re.org
Subject: Re: Several out of bounds reads in ProFTPD

On Fri, Mar 11, 2016 at 05:25:15PM +0100, Hanno Böck wrote:
> https://blog.fuzzing-project.org/40-Several-out-of-bounds-reads-in-ProFTPD.html
> 
> The latest releases of ProFTPD 1.3.5a and 1.3.6rc2 fix several out of
> bounds read issues. I discovered these issues by running the test suite
> with Address Sanitizer enabled.

Can you elaborate on the impact? Do any of these allow a user to crash the ftpd or
can the user merely terminate  her own FTP session?

Cheers,
        Moritz

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.