GLSA Bodhisattva


Joined: 13 Jun 2003 Posts: 4087 Location: Dresden, Germany
|
Posted: Sun Jul 04, 2004 7:47 pm Post subject: [ GLSA 200407-04 ] Pure-FTPd: Potential DoS when maximum con |
|
|
Gentoo Linux Security Advisory
Title: Pure-FTPd: Potential DoS when maximum connections is reached (GLSA 200407-04)
Severity: normal
Exploitable: remote
Date: July 04, 2004
Updated: May 22, 2006
Bug(s): #54590
ID: 200407-04
Synopsis
Pure-FTPd contains a bug potentially allowing a Denial of Service attack when the maximum number of connections is reached.
Background
Pure-FTPd is a fast, production-quality and standards-compliant FTP server.
Affected Packages
Package: net-ftp/pure-ftpd
Vulnerable: <= 1.0.18
Unaffected: >= 1.0.18-r1
Architectures: All supported architectures
Description
Pure-FTPd contains a bug in the accept_client function handling the setup of new connections.
Impact
When the maximum number of connections is reached an attacker could exploit this vulnerability to perform a Denial of Service attack.
Workaround
There is no known workaround at this time. All users are encouraged to upgrade to the latest available version.
Resolution
All Pure-FTPd users should upgrade to the latest stable version: Code: | # emerge sync
# emerge -pv ">=net-ftp/pure-ftpd-1.0.18-r1"
# emerge ">=net-ftp/pure-ftpd-1.0.18-r1" |
References
Pure-FTPd website
CVE-2004-0656
Last edited by GLSA on Tue May 23, 2006 4:17 am; edited 2 times in total |
|