[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1978.0. "Is ftpxd vulnerable to signal handling problem?" by MEOC02::JANKOWSKI () Thu May 29 1997 21:32

    CERT has just published an advisory on vulnerabilities of ftpd.
    The problem is in a race condition during signal handling.
    This has originally been published by AUSTCERT on 29JAN97.
    CERT* Advisory CA-97.16
    Original issue date: May 29, 1997
    
    There are already patches available for DU:
    
    >     ftp://ftp.service.digital.com/patches/public/dunix
    >
    >     VERSION  KIT ID            SIZE     CHECK SUM
    >     -------  ----------------  ------  --------------
    >     v3.2g   SSRT0448U_v32g.tar 296960  32064  290
    >     v4.0    SSRT0448U_v40.tar  542720  07434  530
    >     v4.0a   SSRT0448U_v40a.tar 542720  43691  530
    >     v4.0b   SSRT0448U_v40b.tar 471040  45701  460
    >
    
    Would ftpxd be vulnerable the same way ftpd was?
    
    Regards,
    
    Chris Jankowski
    Melbourne Australia
    
T.RTitleUserPersonal
Name
DateLines
1978.1WOTVAX::16.42.4.61::[email protected]I'm back - as a matter of factMon Jun 02 1997 11:437
Just been asked the same question by a VERY VERY major customer - who go by 
the name of BT/MCI.

Could someone please respond fairly quickly....

Thanks,
Stuart