version 1.255, 2000/07/05 22:40:38 |
version 1.256, 2000/07/05 22:53:09 |
|
|
<li><font color=#009000><strong>019: SECURITY FIX: July 5, 2000</strong></font><br> |
<li><font color=#009000><strong>019: SECURITY FIX: July 5, 2000</strong></font><br> |
Just like pretty much all the other unix ftp daemons on the planet, |
Just like pretty much all the other unix ftp daemons on the planet, |
ftpd had a remote root hole in it. Luckily, ftpd was not enabled by default. |
ftpd had a remote root hole in it. Luckily, ftpd was not enabled by default. |
The problem exists if anonymous ftp is enabled, or if a hostile user has a |
The problem exists if anonymous ftp is enabled. |
valid login. |
|
<br> |
<br> |
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/019_ftpd.patch> |
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/019_ftpd.patch> |
A source code patch exists which remedies this problem.</a> |
A source code patch exists which remedies this problem.</a> |