Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200405-09 ] ProFTPD Access Control List bypass vulnerability
Date: Wed, 19 May 2004 12:06:11
Message-Id: 20040519120339.GQ26130@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200405-09
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: ProFTPD Access Control List bypass vulnerability
9 Date: May 19, 2004
10 Bugs: #49496
11 ID: 200405-09
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Version 1.2.9 of ProFTPD introduced a vulnerability that causes
19 CIDR-based Access Control Lists (ACLs) to be treated as "AllowAll",
20 thereby allowing remote users full access to files available to the
21 FTP daemon.
22
23 Background
24 ==========
25
26 ProFTPD is an FTP daemon.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 net-ftp/proftpd == 1.2.9-r1 >= 1.2.9-r2
35 1 net-ftp/proftpd == 1.2.9 >= 1.2.9-r2
36
37 Description
38 ===========
39
40 ProFTPD 1.2.9 introduced a vulnerability that allows CIDR-based ACLs
41 (such as 10.0.0.1/24) to be bypassed. The CIDR ACLs are disregarded,
42 with the net effect being similar to an "AllowAll" directive.
43
44 Impact
45 ======
46
47 This vulnerability may allow unauthorized files, including critical
48 system files to be downloaded and/or modified, thereby allowing a
49 potential remote compromise of the server.
50
51 Workaround
52 ==========
53
54 Users may work around the problem by avoiding use of CIDR-based ACLs.
55
56 Resolution
57 ==========
58
59 ProFTPD users are encouraged to upgrade to the latest version of the
60 package:
61
62 # emerge sync
63
64 # emerge -pv ">=net-ftp/proftpd-1.2.9-r2"
65 # emerge ">=net-ftp/proftpd-1.2.9-r2"
66
67 References
68 ==========
69
70 [ 1 ] CAN-2004-0432
71 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0432
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 http://security.gentoo.org/glsa/glsa-200405-09.xml
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 http://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2004 Gentoo Technologies, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 http://creativecommons.org/licenses/by-sa/1.0