DSA-2606-1 proftpd-dfsg -- symlink race

Related Vulnerabilities: CVE-2012-6095  

It has been discovered that in ProFTPd, an FTP server, an attacker on the same physical host as the server may be able to perform a symlink attack allowing to elevate privileges in some configurations. For the stable distribution (squeeze), this problem has been fixed in version 1.3.3a-6squeeze6. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 1.3.4a-3. We recommend that you upgrade your proftpd-dfsg packages.

Debian Security Advisory

DSA-2606-1 proftpd-dfsg -- symlink race

Date Reported:
13 Jan 2013
Affected Packages:
proftpd-dfsg
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 697524.
In Mitre's CVE dictionary: CVE-2012-6095.
More information:

It has been discovered that in ProFTPd, an FTP server, an attacker on the same physical host as the server may be able to perform a symlink attack allowing to elevate privileges in some configurations.

For the stable distribution (squeeze), this problem has been fixed in version 1.3.3a-6squeeze6.

For the testing distribution (wheezy), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 1.3.4a-3.

We recommend that you upgrade your proftpd-dfsg packages.