[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-Disclosure] Fwd: solution to wu-ftpd + tar program execution
- To: full-disclosure@xxxxxxxxxxxxxxxx
- Subject: [Full-Disclosure] Fwd: solution to wu-ftpd + tar program execution
- From: "smith jerome" <securebox@xxxxxxxxxxx>
- Date: Mon, 08 Sep 2003 11:59:34 +0300
This has been known for a long time:
http://www.security-express.com/archives/bugtraq/1999-q4/0405.html
There is an easy solution to this which don't cut functionality:
in ftpconversions place " -- " before "%s" in every line which has tar
(probably on all lines is a good idea).
" -- " terminates the arguments passed to tar, so programs can't be
injected.
linux distributions were notified about the solution, debian released an
advisory at:
http://www.debian.org/security/2003/dsa-377
georgi
_________________________________________________________________
Add photos to your messages with MSN 8. Get 2 months FREE*.
http://join.msn.com/?page=features/featuredemail
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html