Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 11 Feb 2009 11:35:26 -0700
From: Vincent Danen <vdanen@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley@...us.mitre.org
Subject: CVE request for proftpd

An SQL injection vulnerability in proftpd was reported on bugtraq
yesterday that could allow a user to login to proftpd with any password
if they use mysql for authentication (and, presumably, postgresql).

References:

http://www.securityfocus.com/archive/1/500823/30/0/threaded
http://bugs.gentoo.org/show_bug.cgi?id=258450
http://bugs.proftpd.org/show_bug.cgi?id=3180
https://bugzilla.redhat.com/show_bug.cgi?id=485125

Could we get a CVE name assigned please?

Thanks.

-- 
Vincent Danen / Red Hat Security Response Team 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.