漏洞描述
ProFTPD versions before 1.3.3c contain directory traversal vulnerabilities in the mod_site_misc module. The vulnerability allows attackers to traverse directories and potentially overwrite arbitrary files on the system through crafted input to commands like SITE MKDIR and other SITE commands.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
bugs.proftpd.orghttp://bugs.proftpd.org/show_bug.cgi?id=3519↗lists.fedoraproject.orghttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050687.html↗lists.fedoraproject.orghttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050703.html↗lists.fedoraproject.orghttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050726.html↗slackware.comhttp://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.498209↗