Release date:
Updated on:
Affected Systems:
Vsftpd 2.3.x
Description:
--------------------------------------------------------------------------------
Vsftpd is short for Very Secure FTP daemon and is a Secure FTP server on UNIX platforms.
Vsftpd 2.3.4 is installed with backdoor code. Remote attackers can exploit this vulnerability to control the affected system.
This vulnerability is caused by a backdoor vsftpd 2.3.4 source code package (vsftpd-2.3.4.tar.gz) released through the project master server ).
<* Source: Mathias Kresin
Link: http://scarybeastsecurity.blogspot.com/2011/07/alert-vsftpd-download-backdoored.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Vsftpd
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://vsftpd.beasts.org/