store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Fri May 24, 2013 4:50 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 
Author Message
 Post subject: ProFTPD Character Encoding SQL Injection Vulnerability
Unread postPosted: Sat Feb 07, 2009 7:22 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3248
Location: Chantilly, VA
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2
http://bugs.proftpd.org/show_bug.cgi?id=3173

Affects ProFTPD 1.3.1 (but NOT earlier versions or 1.3.2) that have NLS
support enabled. If your LANG environment variable uses the "C" or "POSIX"
locale, you are not vulnerable.

Successful exploitation requires that NLS support is enabled.

Solution:
Update to version 1.3.2.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: ProFTPD Character Encoding SQL Injection Vulnerability
Unread postPosted: Sun Feb 08, 2009 8:16 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Does Plesk's ProFTPd have NLS (whatever it is) enabled by default? Or how can we check? And if one need to upgrade, how would we go about doing that so we don't mess up Plesk?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: ProFTPD Character Encoding SQL Injection Vulnerability
Unread postPosted: Sat Feb 28, 2009 10:29 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Mar 10, 2008 9:12 pm
Posts: 475
Location: Southampton, UK
Yeah ditto. I got no idea what NLS is, or if it's a default.

_________________
Matt

"Given that God is infinite, and that the universe is also infinite... would you like a toasted teacake?"

about.me/mattauckland
twitter.com/mattauckland


Top
 Profile  
 
 Post subject: Re: ProFTPD Character Encoding SQL Injection Vulnerability
Unread postPosted: Wed Apr 01, 2009 10:25 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
I googled it. And If what I found is correct NLS has to do with locale.
And also I found that in plesk 8.3 it is a default ...

Offcourse source is google.

The atomic repository instantly installs the 1.3.2 and the problem is solved :)

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: ProFTPD Character Encoding SQL Injection Vulnerability
Unread postPosted: Thu Apr 02, 2009 5:01 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
Their 1.3.2 also doesnt have qouta support last I tried, so anyone using quota support in FTP will be broken, and the FTP server wont spawn on demand processes.


Top
 Profile  
 
 Post subject: Re: ProFTPD Character Encoding SQL Injection Vulnerability
Unread postPosted: Thu Apr 02, 2009 5:23 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
It does now :P As of 1.3.2-5


Top
 Profile  
 
 Post subject: Re: ProFTPD Character Encoding SQL Injection Vulnerability
Unread postPosted: Thu Apr 02, 2009 6:53 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Thanks Scott!

However I can't find the SRPM for -5 can you check?

Thanks!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group