Bugtraq mailing list archives

Re: Memory leakage in proftpd leads to remote DoS


From: tj () RAD GEOLOGY WASHINGTON EDU
Date: Wed, 20 Dec 2000 11:48:06 -0800

I've tested on proftd-1.2.0rc2 and people confirmed that this bug exist in
the latest CVS version.

I had no time to look at the code so no patch is currently available.
Developers have just been informed.

+--------------------------------------------------------------------+
| Wojciech Purczynski   wp () elzabsoft pl  http://www.elzabsoft.pl/~wp |
| GSM: +48604432981   Linux Administrator   SMS: wp-sms () elzabsoft pl |
+------ Public GnuPG Key:  http://www.elzabsoft.pl/~wp/gpg.asc ------+

The developers of proftpd have tried to confirm this bug, using scripts to
issue the SIZE command for hundred thousands of iterations, and failed to
verify that it does indeed exist.

Versions of proftpd tested: pre10, rc1, rc2, and CVS.  All failed to show
symptoms of this memory leak.

----------------------------------------------------------------------------
TJ Saunders                             tj () rad geology washington edu
System Administrator                    Phone: (206) 685-8266
Remote Sensing Lab                      Fax: (206) 685-2379
University of Washington
----------------------------------------------------------------------------


Current thread: