ProFTPD CIDR Access Control Rule Bypass Vulnerability
BID:10252
Info
ProFTPD CIDR Access Control Rule Bypass Vulnerability
| Bugtraq ID: | 10252 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0432 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | The individual that discovered this vulnerability is currently unknown. |
| Vulnerable: |
Turbolinux Turbolinux Server 10.0 Turbolinux Appliance Server 2.0 Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Enterprise Linux 2.0 ProFTPD Project ProFTPD 1.2.9 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Gentoo Linux 1.2 Gentoo Linux 1.1 a Gentoo Linux 0.7 Gentoo Linux 0.5 |
| Not Vulnerable: | |
Discussion
ProFTPD CIDR Access Control Rule Bypass Vulnerability
ProFTPD is prone to a vulnerability that an attacker could exploit to bypass an Access Control List (ACL). The issue was reportedly introduced when a 'portability workaround' was applied to ProFTPD 1.2.9.
This vulnerability may lead a system administrator into a false sense of security, where access to the ProFTPD server is believed to be restricted by ACLs, but in reality the access restrictions will not be enforced at all.
ProFTPD is prone to a vulnerability that an attacker could exploit to bypass an Access Control List (ACL). The issue was reportedly introduced when a 'portability workaround' was applied to ProFTPD 1.2.9.
This vulnerability may lead a system administrator into a false sense of security, where access to the ProFTPD server is believed to be restricted by ACLs, but in reality the access restrictions will not be enforced at all.
Exploit / POC
ProFTPD CIDR Access Control Rule Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
ProFTPD CIDR Access Control Rule Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
ProFTPD Project ProFTPD 1.2.9
Solution:
Updates are available. Please see the references for details.
ProFTPD Project ProFTPD 1.2.9
-
Trustix proftpd-1.2.9-7tr.i586.rpm
Secure Linux 2.1 & Secure Enterprise Linux 2
ftp://ftp.trustix.org/pub/trustix/updates/