vsftpd Compromised Source Packages Backdoor Vulnerability
BID:48539
Info
vsftpd Compromised Source Packages Backdoor Vulnerability
| Bugtraq ID: | 48539 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2011 12:00AM |
| Updated: | Jul 05 2011 10:50AM |
| Credit: | Mathias Kresin |
| Vulnerable: |
Vsftpd Vsftpd 2.3.4 |
| Not Vulnerable: | |
Discussion
vsftpd Compromised Source Packages Backdoor Vulnerability
vsftpd is prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application.
The vsftpd 2.3.4 source package is affected.
vsftpd is prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application.
The vsftpd 2.3.4 source package is affected.
Exploit / POC
vsftpd Compromised Source Packages Backdoor Vulnerability
An attacker can use readily available tools to exploit this issue.
The following exploit is available:
An attacker can use readily available tools to exploit this issue.
The following exploit is available:
Solution / Fix
vsftpd Compromised Source Packages Backdoor Vulnerability
Solution:
The repaired package can be downloaded from https://security.appspot.com/vsftpd.html. Please validate the package with its signature.
Solution:
The repaired package can be downloaded from https://security.appspot.com/vsftpd.html. Please validate the package with its signature.
References
vsftpd Compromised Source Packages Backdoor Vulnerability
References:
References:
- Alert: vsftpd download backdoored (Chris)
- Product Homepage (vsftpd)
- Vsftpd Homepage (Vsftpd)