ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/10252 | vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16038 | vdb entry |
http://marc.info/?l=bugtraq&m=108335051011341&w=2 | mailing list |
http://bugs.proftpd.org/show_bug.cgi?id=2267 | |
http://marc.info/?l=bugtraq&m=108335030208523&w=2 | vendor advisory |
http://secunia.com/advisories/11527 | third party advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2004:041 | vendor advisory |