[22225] in bugtraq
Re: Local exploit for TrollFTPD-1.26
daemon@ATHENA.MIT.EDU (Jedi/Sector One (Frank DENIS))
Mon Aug 13 10:13:14 2001
Date: Mon, 13 Aug 2001 11:22:49 +0200
From: "Jedi/Sector One (Frank DENIS)" <j@jedi.claranet.fr>
To: bugtraq@securityfocus.com
Message-ID: <20010813112249.A678@jedi.claranet.fr>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Pure-FTPd is a derivative of TrollFTPd 1.26.
However, it doesn't seem to be vulnerable to this attack. The bound
checking added in TrollFTPD 1.27 have already been implemented in the very
first version of Pureftpd.
http://www.pureftpd.org
Best regards,
-Frank.