[15682] in bugtraq

home help back first fref pref prev next nref lref last post

Re: ftpd and setproctitle()

daemon@ATHENA.MIT.EDU (Kris Kennaway)
Fri Jul 7 16:16:03 2000

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.BSF.4.21.0007061337060.10096-100000@freefall.freebsd.org>
Date:         Thu, 6 Jul 2000 13:38:25 -0700
Reply-To: Kris Kennaway <kris@FREEBSD.ORG>
From: Kris Kennaway <kris@FREEBSD.ORG>
X-To:         Theo de Raadt <deraadt@CVS.OPENBSD.ORG>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <200007060905.e6695iF29634@cvs.openbsd.org>

-----BEGIN PGP SIGNED MESSAGE-----

On Thu, 6 Jul 2000, Theo de Raadt wrote:

> Well, while everyone is talking about setproctitle affecting wuftpd,
> I should probably note that it even affects the OpenBSD ftpd.  In fact,
> looking around, it looks like it might affect everyone's ftpd.

Fortunately, FreeBSD fixed this back in 1996, so all versions since 2.2.0
are unaffected. We are however auditing the system ftpd and other
utilities for instances of this vulnerability.

Kris

- --
In God we Trust -- all others must submit an X.509 certificate.
    -- Charles Forsythe <forsythe@alum.mit.edu>

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.0i for non-commercial use
Comment: Made with pgp4pine 1.74
Charset: noconv

iQCVAwUBOWTuRlUuHi5z0oilAQF//QQAofUlBewsftbGepAJYSWuu5r8p5DhJIJ6
to9GTFy9WzZauXu+rOx7dnSaymGfh0P2s+VlSpEITxzlDH2OYGHI69WWsYW9mcyl
JtaoIEmoMNcsnaLUJ2MZVQP38LSXtWMmdGkriR4dBaKz4ghZShUzwhXurk9EpkIH
rTuqT5MA2ok=
=9Pgm
-----END PGP SIGNATURE-----

home help back first fref pref prev next nref lref last post