SHARE
Facebook X Pinterest WhatsApp

Debian Security Advisory: proftp runs as root, /var symlink removal

Written By
thumbnail
Web Webster
Web Webster
Mar 7, 2001

Date: Tue, 6 Mar 2001 19:02:53 -0700
From: debian-security-announce@LISTS.DEBIAN.ORG
To: BUGTRAQ@SECURITYFOCUS.COM
Subject: [SECURITY] [DSA-032-1] proftp runs as root, /var symlink
removal


Debian Security Advisory DSA-032-1                                      security@debian.org
http://www.debian.org/security/                                   Wichert Akkerman 
March  7, 2001


Package: proftpd
Vulnerability: proftpd running as root, /var symlink removal
Debian-specific: yes

The following problems have been reported for the version of
proftpd in Debian 2.2 (potato):

1. There is a configuration error in the postinst script, when
the user enters ‘yes’, when asked if anonymous access should be
enabled. The postinst script wrongly leaves the ‘run as uid/gid
root’ configuration option in /etc/proftpd.conf, and adds a ‘run as
uid/gid nobody’ option that has no effect.

2. There is a bug that comes up when /var is a symlink, and
proftpd is restarted. When stopping proftpd, the /var symlink is
removed; when it’s started again a file named /var is created.

The above problems have been corrected in
proftpd-1.2.0pre10-2.0potato1. We recommend you upgrade your
proftpd package immediately.

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 2.2 alias potato


Potato was released for the alpha, arm, i386, m68k, powerpc and
sparc architectures.

Source archives:

http://security.debian.org/dists/stable/updates/main/source/proftpd_1.2.0pre10-2.0potato1.diff.gz

MD5 checksum: d75281d5332b005efd94ad0ff5ac3f63

http://security.debian.org/dists/stable/updates/main/source/proftpd_1.2.0pre10-2.0potato1.dsc

MD5 checksum: 8ff4de189c0b986ab4496ef7ae6467f4

http://security.debian.org/dists/stable/updates/main/source/proftpd_1.2.0pre10.orig.tar.gz

MD5 checksum: a1c25e59bb4281e2f83000796dc52388

Alpha architecture:

http://security.debian.org/dists/stable/updates/main/binary-alpha/proftpd_1.2.0pre10-2.0potato1_alpha.deb

MD5 checksum: 2e3d924a93692fc546f76fadf6e35cf7

ARM architecture:

http://security.debian.org/dists/stable/updates/main/binary-arm/proftpd_1.2.0pre10-2.0potato1_arm.deb

MD5 checksum: 2e2e9a921f45c6c73f0c0a1ba2c7fb13

Intel ia32 architecture:

http://security.debian.org/dists/stable/updates/main/binary-i386/proftpd_1.2.0pre10-2.0potato1_i386.deb

MD5 checksum: 9c0ff3c87e4802316081775fcf80c5d2

Motorola 680×0 architecture:

http://security.debian.org/dists/stable/updates/main/binary-m68k/proftpd_1.2.0pre10-2.0potato1_m68k.deb

MD5 checksum: 615709bf8777da7939217cf316c529b7

PowerPC architecture:

http://security.debian.org/dists/stable/updates/main/binary-powerpc/proftpd_1.2.0pre10-2.0potato1_powerpc.deb

MD5 checksum: 5a384113e857ba4a0b6bdcfce62ca880

Sun Sparc architecture:

http://security.debian.org/dists/stable/updates/main/binary-sparc/proftpd_1.2.0pre10-2.0potato1_sparc.deb

MD5 checksum: c99f335bca49f98867b1a9c473c97edc

These files will be moved into ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/
soon.

For not yet released architectures please refer to the
appropriate directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/
.


For apt-get: deb http://security.debian.org/
stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security
dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>’ and http://packages.debian.org/<pkg>

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

A Thorough Approach to Improve the Privacy and Security of Your Linux PC
Damien
Oct 24, 2024
Several Russian Maintainers Removed From Linux Kernel Due To Compliance Concerns
Senthil Kumar
Oct 23, 2024
OpenSSH Splits Again: New Authentication Binary Unveiled
Bobby Borisov
Oct 16, 2024
13 Best Free and Open Source Anti-Malware Tools
webmaster
Oct 14, 2024
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.