Description: Phantasmal Phantasmagoria has reported a vulnerability in ProFTPD, which potentially can be exploited by malicious users to compromise a vulnerable system.
The vulnerability is caused due to two off-by-one errors in the "_xlate_ascii_write()" function. These can eg. be exploited by uploading and then retrieving ("RETR") a specially crafted file.
Successful exploitation may allow execution of arbitrary code with the privileges of ProFTPD.
The vulnerability has been reported in the following versions:
* 1.2.7/1.2.7p
* 1.2.8/1.2.8p
* 1.2.9rc1/1.2.9rc1p
* 1.2.9rc2/1.2.9rc2p
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.