Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 09 Sep 1999 13:17:52 -0600
From:      Warner Losh <imp@village.org>
To:        Ruslan Ermilov <ru@ucb.crimea.ua>
Cc:        "Rashid N. Achilov" <shelton@sentry.granch.ru>, Bill Fink <bill@billfink.com>, security@FreeBSD.ORG
Subject:   Re: FTP Vulnerability 
Message-ID:  <199909091917.NAA30788@harmony.village.org>
In-Reply-To: Your message of "Thu, 09 Sep 1999 17:09:40 %2B0300." <19990909170940.B51179@relay.ucb.crimea.ua> 
References:  <19990909170940.B51179@relay.ucb.crimea.ua>  <19990909162255.A15548@relay.ucb.crimea.ua> <Pine.BSF.4.10.9909092051490.59511-100000@sentry.granch.ru> 

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----

In message <19990909170940.B51179@relay.ucb.crimea.ua> Ruslan Ermilov writes:
: Grr...  Advisory refers to version of the FreeBSD port after 1999/08/30:

Let me also explicitly state that the security officer's policy is to
only support the FreeBSD ports tree for "re-issue" advisories.  This
is a recent change and I'm trying to figure out the exact parameters
of the change, so feedback would be helpful.  At the moment, if you
aren't using ports for things like wu-ftpd, then you are on your own
for doing research to see what you need to do to your, potentially
random, system to make sure that it is not vulnerable.  I reread the
advisory and will be the first to admit that it wasn't the clearest
advisory that I'd written in this area.

In the future I'll try to make sure that I state this explicitly and
clearly.  Something like

The wu-ftpd FreeBSD port in /usr/ports/ftp/wu-ftpd has been ungraded
on August 30, 1999 to incorporate changes recommended by the wu-ftpd
development team to eliminate a potential vulnerability that would
allow remote users to gain root.  You are strongly urged to upgrade
/usr/ports/ftp/wu-ftpd to a version newer than that date, rebuild and
reinstall wu-ftpd to eliminate this weakness on your system.

Warner

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface

iQCVAwUBN9gH31UuHi5z0oilAQF12QP+NpoWbo83qlcfxFUsNJhrrz5iv2Gtl/Xv
485APBYuJOm8o6w4t9MxV16DP04m0DKZHCa9E0SwZHKsnsEqVmOrN1yEmjwRRqpw
6VKVXMt6EpSa4JNi5jK/zwsFn1Bq4TAnc7c4VqkLHb14XUbFQRDIMpQhxeo17UC2
jgD0gHMMs6I=
=vFR9
-----END PGP SIGNATURE-----


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199909091917.NAA30788>