oss-sec mailing list archives
Re: CVE id request: ftpd
From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 30 Sep 2008 16:55:36 -0400 (EDT)
On Tue, 30 Sep 2008, Josh Bressers wrote:
----- "Steven M. Christey" <coley () linus mitre org> wrote:CVE-2008-4247 is for *BSD's ftpd; CVE-2008-4242 is for ProFTPD.I'm pretty sure this also affects at least wu-ftpd, but looking into what else is on my list of things to do. From my quick investigation, the file in question (ftpcmd.y) is in lots of other ftp daemons, and the code is eerily similar.
If the same file is affected, and it's known, then technically these all stem from the same bad code and thus retain the same CVE. We split ProFTPD from ftpd largely based on ProFTPD's statement that "it's an independent source tree from the ground up." - Steve
Current thread:
- CVE id request: ftpd Steffen Joeris (Sep 29)
- Re: CVE id request: ftpd Robert Buchholz (Sep 29)
- Re: CVE id request: ftpd Steven M. Christey (Sep 30)
- <Possible follow-ups>
- Re: CVE id request: ftpd Josh Bressers (Sep 30)
- Re: CVE id request: ftpd Steven M. Christey (Sep 30)