Summary
The remote host is missing an update to proftpd
announced via advisory FEDORA-2009-9386.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update proftpd' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-9386
Insight
Update Information:
This update has a large number of changes from previous Fedora packages the
highlights are as follows:
- Update to upstream release 1.3.2a
- Fix SQL injection vulnerability at login (#485125, CVE-2009-0542) - Fix SELinux compatibility (#498375)
- Fix audit logging (#506735)
- Fix default configuration (#509251)
- Many new loadable modules including mod_ctrls_admin and mod_wrap2 - National Language Support (RFC 2640)
- Enable/disable common features in /etc/sysconfig/proftpd
ChangeLog:
* Mon Sep 7 2009 Paul Howarth 1.3.2a-5
- Add upstream patch for MLSD with dirnames containing glob chars (#521634) * Wed Sep 2 2009 Paul Howarth 1.3.2a-4
- New DSO module: mod_exec (#520214)
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-0542 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities