FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-6170

This CVE name corresponds to:

Entered Topic
2006-12-21 proftpd -- remote code execution vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-6170
Phase Assigned(20061130)

Description

Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allows remote attackers to execute arbitrary code via a large data length argument, a different vulnerability than CVE-2006-5815.

References

Source Reference
BUGTRAQ 20061121 Re: [ MDKSA-2006:217 ] - Updated proftpd packages fix vulnerabilities
BUGTRAQ 20061128 ProFTPD mod_tls pre-authentication buffer overflow
BUGTRAQ 20061129 Re: ProFTPD mod_tls pre-authentication buffer overflow
FULLDISC 20061128 ProFTPD mod_tls pre-authentication buffer overflow
MISC http://elegerov.blogspot.com/2006/10/do-you-remember-2-years-old-overflow.html
CONFIRM https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=214820
DEBIAN DSA-1222
GENTOO GLSA-200611-26
MANDRIVA MDKSA-2006:217-1
SLACKWARE SSA:2006-335-02
TRUSTIX 2006-0066
BID 21326
VUPEN ADV-2006-4745
SECUNIA 23141
SECUNIA 23174
SECUNIA 23179
SECUNIA 23184
SECUNIA 23207
XF proftpd-modtls-bo(30554)