Release date:
Updated on:
Affected Systems:
ProFTPD Project ProFTPD 1.3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57172
ProFTPD is a free open source software released by GPL-licensed.
ProFTPD 1.3.3 and other versions have a condition competition problem when processing the MKD and xmkd ftp commands, which can be used to improve permissions, such as rewriting arbitrary files through symlink attacks.
<* Source: Jann Horn
Link: http://secunia.com/advisories/51761/
Http://bugs.proftpd.org/show_bug.cgi? Id = 3841
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ProFTPD Project
---------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.proftpd.org/