Executive Summary

Summary
Title New ftpd-ssl packages fix arbitrary code execution
Informations
Name DSA-896 First vendor Publication 2005-11-15
Vendor Debian Last vendor Modification 2005-11-15
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A buffer overflow has been discovered in ftpd-ssl, a simple BSD FTP server with SSL encryption support, that could lead to the execution of arbitrary code.

The old stable distribution (woody) does not contain linux-ftpd-ssl packages.

For the stable distribution (sarge) this problem has been fixed in version 0.17.18+0.3-3sarge1

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your ftpd-ssl package.

Original Source

Url : http://www.debian.org/security/2005/dsa-896

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

OpenVAS Exploits

Date Description
2008-09-24 Name : Gentoo Security Advisory GLSA 200511-11 (linux-ftpd-ssl)
File : nvt/glsa_200511_11.nasl
2008-01-17 Name : Debian Security Advisory DSA 896-1 (linux-ftpd-ssl)
File : nvt/deb_896_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
20530 Linux-ftpd-ssl FTP Server Response Remote Overflow

A remote overflow exists in linux-ftpd-ssl. The SSL code fails to validate input to the vsprintf() function resulting in a stack-based buffer overflow. With a specially crafted request which generates more than 2048 bytes of response from the server, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.

Nessus® Vulnerability Scanner

Date Description
2006-10-14 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-896.nasl - Type : ACT_GATHER_INFO
2005-11-15 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200511-11.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:34:39
  • Multiple Updates