PDA

View Full Version : ProFTPD 1.2.9 Security Update?



woeger
11-02-2003, 09:20 PM
I understand there is nasty security bug in ProFTPD versions prior to the new 1.2.9 version where someone can upload a specific text file and download it again using FTP to gain root access to the server. Is there a patched ProFTPD coming soon to plug this bug that works with DirectAdmin?

The security bug with ProFTPD is described here:
http://xforce.iss.net/xforce/alerts/id/154

woeger
11-02-2003, 09:30 PM
I found my own answer to this question about a ProFTPD security patch in another thread:
http://www.directadmin.com/forum/showthread.php?s=&threadid=739&highlight=proftpd

Thanks! This is a patched 1.2.8 ProFTPD version. Are there plans for DirectAdmin to include a 1.2.9 version, or is that not necessary?

l0rdphi1
11-03-2003, 11:05 AM
I'm sure the version distobuted with DirectAdmin will be updated when they get around to it.

Ryan
11-09-2003, 10:20 AM
DirectAdmin have this been updated yet? Can we just use the standard proftpd and compile it ourselves?

DirectAdmin Support
11-09-2003, 02:01 PM
Hello,

You are free to recomile it yourself. I'll try and get the rpm's/tgz out for 1.2.9 soon. I'll post to the updates section when I do.

John