[Bug 219938] CVE-2006-6563: proftpd < 1.3.1rc1 mod_ctrls buffer overflow

bugzilla at redhat.com bugzilla at redhat.com
Mon Dec 18 19:32:47 UTC 2006


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.

Summary: CVE-2006-6563: proftpd < 1.3.1rc1 mod_ctrls buffer overflow


https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=219938





------- Additional Comments From kaboom at oobleck.net  2006-12-18 14:32 EST -------
1.3.1rc1 builds for me on fc6

Configured as

 ./configure --libexecdir=/usr/libexec/proftpd --localstatedir=/var/run --ena
ble-ctrls --enable-facl --enable-dso --enable-ipv6 --with-libraries=/usr/lib/mys
ql --with-includes=/usr/include/mysql --with-modules=mod_readme:mod_auth_pam:mod
_tls --with-shared=mod_ldap:mod_sql:mod_sql_mysql:mod_sql_postgres:mod_quotatab:
mod_quotatab_file:mod_quotatab_ldap:mod_quotatab_sql

(same as fe6 rpm, built on ia32)

That's using the stock upstream code, I haven't added the shipped patches yet....

-- 
Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.




More information about the Fedora-security-list mailing list