[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: wu-ftp segfault



On Wed, 3 May 2000, Bryan Andersen wrote:

> Check your version number for WU-FTPD.  It should be 2.6.0 or higher.
~> dpkg --status wu-ftpd
Package: wu-ftpd
Status: install ok installed
Priority: optional
Section: net
Installed-Size: 415
Maintainer: Chris Butler <chrisb@sandy.force9.co.uk>
Version: 2.6.0-5

> A quick jump over to CERT shows you need to have version 2.6.0 of 
> wu-ftpd or latter to avoid the known attacks against it.  Looking at
> both the frozen and unstable releases we should be up to date.  It may
> be that there is a new exploit.
The version should be OK.  How to proceed now?
There were alltogether 5  
   wu-ftpd[.*]: exiting on signal 11: Segmentation fault
which occured in a time of 45 minutes.  All connections while this
time were established from ith2-d69.twcny.rr.com .

Could it be a potentionally exploit or a bug in wu-ftpd.  I do logcheck
observations since one month and never detected such things before.

Kind regards

        Andreas.



Reply to: