Debian Security Advisory: New version of proftpd fixes remote exploits | Linux Today

Debian Security Advisory: New version of proftpd fixes remote exploits

Written By
Web Webster
Web Webster
Nov 11, 1999

Date: Thu, 11 Nov 1999 16:14:07 +0100
From: Wichert Akkerman <wichert@soil.nl>
To: debian-security-announce@lists.debian.org

—–BEGIN PGP SIGNED MESSAGE—–


Debian Security Advisory security@debian.org
http://www.debian.org/security/
Wichert Akkerman
November 11, 1999


The proftpd version that was distributed in Debian GNU/Linux 2.1
had several buffer overruns that could be exploited by remote
attackers. A short list of problems:
* user input was used in snprintf() without sufficient checks
* there was an overflow in the log_xfer() routine
* you could overflow a buffer by using very long pathnames

Please not that this is not meant to be an exhaustive list.

In addition to the security fixes a couple of Y2K problems were
also fixed.

We have made a new package with version 1.2.0pre9-4 to address
these issues, and we recommend to upgrade your proftpd package
immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

Debian GNU/Linux 2.1 alias slink


This version of Debian was released only for Intel, the Motorola
680×0, the alpha and the Sun sparc architecture.

Source archives:

http://security.debian.org/dists/stable/updates/source/proftpd_1.2.0pre9-4.diff.gz

MD5 checksum: d703d0e3aea53b480756010189ce38ae

http://security.debian.org/dists/stable/updates/source/proftpd_1.2.0pre9-4.dsc

MD5 checksum: 074aee046bd22429d98d4928bcb8e14e

http://security.debian.org/dists/stable/updates/source/proftpd_1.2.0pre9.orig.tar.gz

MD5 checksum: 3f41477cc398ddd9f8afbf475f8be1a5

Alpha architecture:

http://security.debian.org/dists/stable/updates/binary-alpha/proftpd_1.2.0pre9-4_alpha.deb

MD5 checksum: 1d614aaf48960f233d14b8cd3e206cc3

Intel ia32 architecture:

http://security.debian.org/dists/stable/updates/binary-i386/proftpd_1.2.0pre9-4_i386.deb

MD5 checksum: 26482b8817defe8eef78ff0b3f892a1d

Motorola 680×0 architecture:

http://security.debian.org/dists/stable/updates/binary-m68k/proftpd_1.2.0pre9-4_m68k.deb

MD5 checksum: 0b6c057d5c5895adfac4803b5165306b

Sun Sparc architecture:

http://security.debian.org/dists/stable/updates/binary-sparc/proftpd_1.2.0pre9-4_sparc.deb

MD5 checksum: b13deca3169a6516025cd9ace9beea05

These files will be moved into
ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/
soon.

For not yet released architectures please refer to the
appropriate directory
ftp://ftp.debian.org/debian/dists/sid/binary-$arch/
.

– —


For apt-get: deb
http://security.debian.org/
stable updates
For dpkg-ftp:
ftp://security.debian.org/debian-security
dists/stable/updates
Mailing list: debian-security-announce@lists.debian.org

—–BEGIN PGP SIGNATURE—–
Version: 2.6.3ia
Charset: noconv

iQB1AwUBOCrdGajZR/ntlUftAQG0zAL9ExG5CW6nwLFdfiedRutKScL3SWyPOt7g
Qkd3lu5nRoR2zqU8VjdFwB2W954+ZItlmnNZQubUHqZfylwN1jdEfny/1Oq/a7h7
VA1GA67/c7/DbRamf0aWqkacE34Ylb3J
=nOqF

—–END PGP SIGNATURE—–

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.