Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: ProFTPd 2 open security issues

  1. #1
    Join Date
    Jun 2010
    Beans
    102

    ProFTPd 2 open security issues

    Hi,

    so ProFTPd currently has 2 open security issues in Ubuntu 10.4 LTS (ProFTPd 1.3.2c-1ubuntu0.1). The Telnet IAC processing stack overflow from 2010-10-29, fixed in 1.3.3c, and the newer mod_sql pre-authentication remote root issue from Mid-November, still unpatched by the ProFTPd authors.

    I'm running that FTP server on my system and I'm concerned about my system security. At least the first patch should have been ported a month ago, but the USN list doesn't mention ProFTPd for a long time.

    Should I consider switching to another FTP server, Pure-FTP has been mentioned elsewhere? Or does Ubuntu have a somehow modified version that didn't have those issues in the first place, but nobody mentioning it?

  2. #2
    Join Date
    Jul 2007
    Beans
    414
    Distro
    Xubuntu 13.04 Raring Ringtail

    Re: ProFTPd 2 open security issues

    Quote Originally Posted by LonelyPixel View Post
    Hi,

    so ProFTPd currently has 2 open security issues in Ubuntu 10.4 LTS (ProFTPd 1.3.2c-1ubuntu0.1). The Telnet IAC processing stack overflow from 2010-10-29, fixed in 1.3.3c, and the newer mod_sql pre-authentication remote root issue from Mid-November, still unpatched by the ProFTPd authors.

    I'm running that FTP server on my system and I'm concerned about my system security. At least the first patch should have been ported a month ago, but the USN list doesn't mention ProFTPd for a long time.

    Should I consider switching to another FTP server, Pure-FTP has been mentioned elsewhere? Or does Ubuntu have a somehow modified version that didn't have those issues in the first place, but nobody mentioning it?
    Have a look at vsftpd to see if it will meet your needs.

  3. #3
    Join Date
    Mar 2006
    Location
    Williams Lake
    Beans
    Hidden!
    Distro
    Ubuntu Development Release

    Re: ProFTPd 2 open security issues

    You could also stop using an ftp server and use sftp, most ftp clients support sftp.

  4. #4
    Join Date
    Jun 2010
    Beans
    102

    Re: ProFTPd 2 open security issues

    Quote Originally Posted by cariboo907 View Post
    You could also stop using an ftp server and use sftp, most ftp clients support sftp.
    I've been thinking about that, but I'm not sure all of my webhosting clients could handle that. Maybe I should just ask them to find out.

  5. #5
    Join Date
    Oct 2009
    Beans
    Hidden!
    Distro
    Ubuntu 22.04 Jammy Jellyfish

    Re: ProFTPd 2 open security issues

    Quote Originally Posted by LonelyPixel View Post
    I've been thinking about that, but I'm not sure all of my webhosting clients could handle that. Maybe I should just ask them to find out.
    Would be a good idea.

    sftp > ftp and a whole heck of a lot easier to set up.
    Come to #ubuntuforums! We have cookies! | Basic Ubuntu Security Guide

    Tomorrow's an illusion and yesterday's a dream, today is a solution...

  6. #6
    Join Date
    Jun 2010
    Beans
    102

    Re: ProFTPd 2 open security issues

    But still, until this is evaluated, ProFTPd remains highly insecure on Ubuntu!

  7. #7
    Join Date
    Oct 2009
    Beans
    Hidden!
    Distro
    Ubuntu 22.04 Jammy Jellyfish

    Re: ProFTPd 2 open security issues

    Quote Originally Posted by LonelyPixel View Post
    But still, until this is evaluated, ProFTPd remains highly insecure on Ubuntu!
    File a bug report on launchpad referencing the vulnerabilities.
    Come to #ubuntuforums! We have cookies! | Basic Ubuntu Security Guide

    Tomorrow's an illusion and yesterday's a dream, today is a solution...

  8. #8
    Join Date
    Jun 2010
    Beans
    102

    Re: ProFTPd 2 open security issues

    Oh, it seems that the first bug was already resolved with the current version. There wasn't even a notice about it. Only the Launchpad entry suggests it.

    The second bug is in mod_sql which is not a standard module of ProFTPD. So I'm not sure whether we can expect a fix for that.

  9. #9
    Join Date
    Nov 2009
    Beans
    919
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: ProFTPd 2 open security issues

    Just read this morning that the source code for ProFTPd was compromised some time prior to last weekend (maybe?). I don't think that would necessarily be a problem for applying updates to an already-installed version, but it might be something to keep at the back of your mind. Looking for a link...

  10. #10
    Join Date
    Nov 2009
    Beans
    919
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: ProFTPd 2 open security issues

    Quote Originally Posted by OpSecShellshock View Post
    Just read this morning that the source code for ProFTPd was compromised some time prior to last weekend (maybe?). I don't think that would necessarily be a problem for applying updates to an already-installed version, but it might be something to keep at the back of your mind. Looking for a link...
    Got it:

    http://www.zdnet.com/blog/security/o...urce-code/7787

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •