Release date: 2011-12-12
Updated on: 2011-12-13
Affected Systems:
Vsftpd 2.3.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51013
Vsftpd is short for Very Secure FTP daemon and is a Secure FTP server on UNIX platforms.
The _ tzfile_read () function of vsftpd has a heap buffer overflow vulnerability. Attackers can exploit this vulnerability to execute arbitrary code and cause DOS.
<* Source: Kingdom (kingcope@gmx.net)
Link: http://dividead.wordpress.com/tag/heap-overflow/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Vsftpd
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://vsftpd.beasts.org/