[4752] in bugtraq
Re: wu-ftpd beta 13 Upload Ownership/Permissions Bug
daemon@ATHENA.MIT.EDU (Robert Zilbauer)
Fri Jun 20 21:28:00 1997
Date: Fri, 20 Jun 1997 12:03:09 -0700
Reply-To: Robert Zilbauer <zilbauer@CTHULHU.EUROPA.COM>
From: Robert Zilbauer <zilbauer@CTHULHU.EUROPA.COM>
To: BUGTRAQ@NETSPACE.ORG
At 11:55 PM 6/19/97 -0500, Michael Brennen wrote:
>There is a potentially serious bug in ftpd.c in wu-ftpd beta 13. I have
>no idea if it exists in previous betas. I don't think this was a problem
>in beta 11, but I've not kept any older source. If you are not running
>beta 13, check this against your source.
[...snip...]
>If upload directive processing fails for the anonymous user, sites that
>depend on upload directives to properly set incoming file permissions
>could find their site security compromised.
Upload directives work fine in beta 12. Must be a new addition to b13.
-----
Robert C. Zilbauer, Jr. Europa Communications Inc
Primary: zilbauer@europa.com Secondary: zilbauer@efn.org
"Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn."