lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <Sea2-F12JzTeCkcB3OV0000fc10@hotmail.com> From: securebox at hotmail.com (smith jerome) Subject: Fwd: solution to wu-ftpd + tar program execution This has been known for a long time: http://www.security-express.com/archives/bugtraq/1999-q4/0405.html There is an easy solution to this which don't cut functionality: in ftpconversions place " -- " before "%s" in every line which has tar (probably on all lines is a good idea). " -- " terminates the arguments passed to tar, so programs can't be injected. linux distributions were notified about the solution, debian released an advisory at: http://www.debian.org/security/2003/dsa-377 georgi _________________________________________________________________ Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail