[4752] in bugtraq

home help back first fref pref prev next nref lref last post

Re: wu-ftpd beta 13 Upload Ownership/Permissions Bug

daemon@ATHENA.MIT.EDU (Robert Zilbauer)
Fri Jun 20 21:28:00 1997

Date: 	Fri, 20 Jun 1997 12:03:09 -0700
Reply-To: Robert Zilbauer <zilbauer@CTHULHU.EUROPA.COM>
From: Robert Zilbauer <zilbauer@CTHULHU.EUROPA.COM>
To: BUGTRAQ@NETSPACE.ORG

At 11:55 PM 6/19/97 -0500, Michael Brennen wrote:
>There is a potentially serious bug in ftpd.c in wu-ftpd beta 13.  I have
>no idea if it exists in previous betas.  I don't think this was a problem
>in beta 11, but I've not kept any older source.  If you are not running
>beta 13, check this against your source.
[...snip...]
>If upload directive processing fails for the anonymous user, sites that
>depend on upload directives to properly set incoming file permissions
>could find their site security compromised.

Upload directives work fine in beta 12. Must be a new addition to b13.

-----
Robert C. Zilbauer, Jr.                          Europa Communications Inc
Primary: zilbauer@europa.com                   Secondary: zilbauer@efn.org

          "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn."

home help back first fref pref prev next nref lref last post