Mandrake update for lftp
Secunia Advisory: SA10437
Release Date: 2003-12-16
Popularity: 6,336 views

Critical:
Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Mandrake Corporate Server 2.x
Mandrake Linux 9.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0963


Description:
MandrakeSoft has issued updated packages for lftp. These fix two vulnerabilities, which potentially can be exploited by malicious people to compromise a vulnerable system.

For more information
SA10427

Solution:
Updated packages:

http://www.mandrakesecure.net/en/ftp.php

Corporate Server 2.1:
701dc411181f76222b9da521ecb918ea corporate/2.1/RPMS/lftp-2.6.0-1.1.C21mdk.i586.rpm
645a7dc1cb448119e396caa811f166f4 corporate/2.1/SRPMS/lftp-2.6.0-1.1.C21mdk.src.rpm

Corporate Server 2.1/x86_64:
4fb0dba34a2bf34eb308302a3c3a539a x86_64/corporate/2.1/RPMS/lftp-2.6.0-1.1.C21mdk.x86_64.rpm
645a7dc1cb448119e396caa811f166f4 x86_64/corporate/2.1/SRPMS/lftp-2.6.0-1.1.C21mdk.src.rpm

Mandrake Linux 9.0:
d25f45fc551ba6dff648b5606cf28f50 9.0/RPMS/lftp-2.6.0-1.1.90mdk.i586.rpm
d61a1547159595711598777db73bab3e 9.0/SRPMS/lftp-2.6.0-1.1.90mdk.src.rpm

Mandrake Linux 9.1:
c4b66d9cd6da996a8b75f8e64f53453f 9.1/RPMS/lftp-2.6.4-2.1.91mdk.i586.rpm
025d21cc6a3e309760ffe36d51fc091a 9.1/SRPMS/lftp-2.6.4-2.1.91mdk.src.rpm

Mandrake Linux 9.1/PPC:
2f282a7fa70ab9d0a8e556ecaf95bfd9 ppc/9.1/RPMS/lftp-2.6.4-2.1.91mdk.ppc.rpm
025d21cc6a3e309760ffe36d51fc091a ppc/9.1/SRPMS/lftp-2.6.4-2.1.91mdk.src.rpm

Mandrake Linux 9.2:
c24d53a5c4566d0ef9155fe427347fa8 9.2/RPMS/lftp-2.6.6-2.1.92mdk.i586.rpm
38cd1ea07bd0e2cbfbfaaf8b84d505e3 9.2/SRPMS/lftp-2.6.6-2.1.92mdk.src.rpm

Mandrake Linux 9.2/AMD64:
72cc8612325d8e985c3bbe40fa34fd8b amd64/9.2/RPMS/lftp-2.6.6-2.1.92mdk.amd64.rpm
38cd1ea07bd0e2cbfbfaaf8b84d505e3 amd64/9.2/SRPMS/lftp-2.6.6-2.1.92mdk.src.rpm

Original Advisory:
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:116

Other References:
SA10427:
http://secunia.com/advisories/10427/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB "gen_rand_string()" Predictable RNG Weakness // 89 views
2. Adobe Flash Player Multiple Vulnerabilities // 78 views
3. Sun Java JDK / JRE Multiple Vulnerabilities // 39 views
4. VLC Media Player Multiple Vulnerabilities // 35 views
5. IBM DB2 Multiple Vulnerabilities // 35 views
6. Microsoft Office Two Code Execution Vulnerabilities // 28 views
7. Microsoft Word Malformed Object Pointer Vulnerability // 27 views
8. libpng "png_push_read_zTXt()" Off-By-One Vulnerability // 27 views
9. Linux Kernel "listxattr" Memory Corruption and CHRP Denial of Service // 27 views
10. Silentum LoginSys Multiple Cross-site Scripting Vulnerabilities // 25 views