From owner-freebsd-questions@FreeBSD.ORG Thu Jul 31 21:04:04 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AA18F37B401 for ; Thu, 31 Jul 2003 21:04:04 -0700 (PDT) Received: from gamma.hostbyk.com (gamma.hostbyk.com [205.214.80.64]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1C05443F75 for ; Thu, 31 Jul 2003 21:04:04 -0700 (PDT) (envelope-from jmhowell@gamma.hostbyk.com) Received: from jmhowell by gamma.hostbyk.com with local (Exim 4.20) id 19iR9I-0003VN-MC for freebsd-questions@freebsd.org; Thu, 31 Jul 2003 22:04:12 -0600 Date: Thu, 31 Jul 2003 22:04:12 -0600 From: "Jerry M. Howell II" To: freebsd-questions@freebsd.org Message-ID: <20030731220412.B860@jmhowell.com> References: <6041B5F2-C383-11D7-A62F-0030656DD690@foolishgames.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: <6041B5F2-C383-11D7-A62F-0030656DD690@foolishgames.com>; from luke@foolishgames.com on Thu, Jul 31, 2003 at 02:18:25PM -0400 X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - gamma.hostbyk.com X-AntiAbuse: Original Domain - freebsd.org X-AntiAbuse: Originator/Caller UID/GID - [32003 32060] / [47 12] X-AntiAbuse: Sender Address Domain - gamma.hostbyk.com Subject: Re: WU FTPD X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 01 Aug 2003 04:04:05 -0000 On Thu, Jul 31, 2003 at 02:18:25PM -0400, Lucas Holt wrote: > There was a vulnerability released today in wu ftpd and I'm unclear if > this would affect the software running on a freebsd system. It appears > to cause problems on linux 2.4.x kernels but not older kernels due to > the way the compiler works. Does anyone know if this problem is > exploitable on freebsd? If not, where should I ask this question? > I'd look for a better alternative for a ftp server anyways. WU is potmarked with tons of security flaws. It can be locked prety tight if you know what your doing but there are beter alternatives. Many ppl have substituted proftp in it's place and pureftp is starting to gain popularity -- Jerry M. Howell II