[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-Disclosure] Fwd: solution to wu-ftpd + tar program execution

This has been known for a long time:

There is an easy solution to this which don't cut functionality:
in ftpconversions place " -- " before "%s" in every line which has tar
(probably on all lines is a good idea).
" -- " terminates the arguments passed to tar, so programs can't be

linux distributions were notified about the solution, debian released an
advisory at:


Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail

Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html