Re: wu-ftp vulnerability

2001-11-28 Thread John Griffiths
At 09:36 PM 11/28/01 -0800, [EMAIL PROTECTED] wrote: >> Thu, Nov 29, 2001 at 12:35:13PM +1100, John Griffiths wrote: >> At 05:22 PM 11/28/01 -0800, Greg Wiley wrote: > >> >http://www.securityfocus.com/archive/1/242750 >> >Debian 2.2 is on the list. >> >> Does this effect wu-ftpd's that don't allow

Re: wu-ftp vulnerability

2001-11-28 Thread greg
> Thu, Nov 29, 2001 at 12:35:13PM +1100, John Griffiths wrote: > At 05:22 PM 11/28/01 -0800, Greg Wiley wrote: > >http://www.securityfocus.com/archive/1/242750 > >Debian 2.2 is on the list. > > Does this effect wu-ftpd's that don't allow anonymous access? > > i.e. if only user's can log on, and

Re: wu-ftp vulnerability

2001-11-28 Thread John Griffiths
At 05:22 PM 11/28/01 -0800, Greg Wiley wrote: >According to /., wu-ftp has a vulnerability that >allows root access to files. Check out: > >http://www.securityfocus.com/archive/1/242750 > >Debian 2.2 is on the list. > >Apologies if this has been discussed already. > Apparently the maintainer is wo

wu-ftp vulnerability

2001-11-28 Thread Greg Wiley
According to /., wu-ftp has a vulnerability that allows root access to files. Check out: http://www.securityfocus.com/archive/1/242750 Debian 2.2 is on the list. Apologies if this has been discussed already. -=greg