Gentoo: proftpd sql inject vulnerability
Summary
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-10
from advisory:
"A SQL Inject exists in ProFTPD server using the mod_sql module to authenticate against PostgreSQL database server. This vulnerability may allow a remote user to login whithout user and password."
Read the full advisory at http://marc.theaimsgroup.com/?l=full-disclosure&m=105597431408016&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running net-ftp/proftpd upgrade to proftpd-1.2.9_rc1 as follows
emerge sync emerge proftpd emerge clean
aliz@gentoo.org - GnuPG key is available at
Resolution
References
Availability
Concerns
Background