Netkit FTP Server: Denial of service — GLSA 200801-17

Netkit FTP Server contains a Denial of Service vulnerability.

Affected packages

net-ftp/netkit-ftpd on all architectures
Affected versions < 0.17-r7
Unaffected versions >= 0.17-r7

Background

net-ftp/netkit-ftpd is the Linux Netkit FTP server with optional SSL support.

Description

Venustech AD-LAB discovered that an FTP client connected to a vulnerable server with passive mode and SSL support can trigger an fclose() function call on an uninitialized stream in ftpd.c.

Impact

A remote attacker can send specially crafted FTP data to a server with passive mode and SSL support, causing the ftpd daemon to crash.

Workaround

Disable passive mode or SSL.

Resolution

All Netkit FTP Server users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-ftp/netkit-ftpd-0.17-r7"

References

Release date
January 29, 2008

Latest revision
January 29, 2008: 01

Severity
normal

Exploitable
remote

Bugzilla entries