int(4385)

Vulnerability Bulletins


Cross-Site request forgery en ProFtpd

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Principiante
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer GNU/Linux
Affected software ProFTPD 1.3.1

Description

Se ha descubierto una vulnerabilidad de tipo Cross-Site request forgery en ProFTPD 1.3.1.

Un atacante remoto podría ejecutar comandos arbitrarios mediante URLs largas especialmente diseñadas.

Exploit público disponible.

Solution



Actualización de software

Debian (DSA-1689-1)

Debian Linux 4.0
Source
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.0-19etch2.dsc
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.0-19etch2.diff.gz
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.0.orig.tar.gz
Arquitectura independiente:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-doc_1.3.0-19etch2_all.deb
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-ldap_1.3.0-19etch2_all.deb
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mysql_1.3.0-19etch2_all.deb
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-pgsql_1.3.0-19etch2_all.deb
Alpha architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_alpha.deb
AMD64 architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_amd64.deb
ARM architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_arm.deb
HP Precision architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_hppa.deb
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_i386.deb
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_ia64.deb
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_mips.deb
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_mipsel.deb
PowerPC architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_powerpc.deb
IBM S/390 architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_s390.deb
Sun Sparc architecture:
http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.0-19etch2_sparc.deb

Standar resources

Property Value
CVE CVE-2008-4242
BID 31289

Other resources

Debian Security Advisory (DSA-1689-1)
http://lists.debian.org/debian-security-announce/2008/msg00282.html

Version history

Version Comments Date
1.0 Aviso emitido 2008-12-22
Ministerio de Defensa
CNI
CCN
CCN-CERT