Oval Definition:
oval:org.mitre.oval:def:8097
Revision Date
:
2014-06-23
Version
:
17
Title
:
DSA-1452 wzdftpd -- denial of service
Description
:
k1tk4t discovered that wzdftpd, a portable, modular, small and efficient ftp server, did not correctly handle the receipt of long usernames. This could allow remote users to cause the daemon to exit.
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2007-5300
DSA-1452
Platform(s)
:
Debian GNU/Linux 3.1
Debian GNU/Linux 4.0
Product(s)
:
wzdftpd
Definition Synopsis
Release section
Debian GNU/Linux 4.0 is installed.
AND
Packages section
wzdftpd-mod-avahi is earlier than 0.8.1-2etch1
OR
wzdftpd-mod-perl is earlier than 0.8.1-2etch1
OR
wzdftpd-mod-tcl is earlier than 0.8.1-2etch1
OR
wzdftpd-dev is earlier than 0.8.1-2etch1
OR
wzdftpd is earlier than 0.8.1-2etch1
OR
wzdftpd-back-mysql is earlier than 0.8.1-2etch1
OR
wzdftpd-back-pgsql is earlier than 0.8.1-2etch1
OR
Release section
Debian GNU/Linux 3.1 is installed
AND
Supported architectures section
Installed architecture is s390
OR
Installed architecture is amd64
OR
Installed architecture is sparc
OR
Installed architecture is m68k
OR
Installed architecture is arm
OR
Installed architecture is i386
OR
Installed architecture is mips
OR
Installed architecture is alpha
OR
Installed architecture is powerpc
OR
Installed architecture is mipsel
OR
Installed architecture is hppa
AND
Packages section
wzdftpd is earlier than 0.5.2-1.1sarge3
OR
wzdftpd-mod-tcl is earlier than 0.5.2-1.1sarge3
OR
wzdftpd-back-mysql is earlier than 0.5.2-1.1sarge3
OR
wzdftpd-mod-perl is earlier than 0.5.2-1.1sarge3
OR
wzdftpd-dev is earlier than 0.5.2-1.1sarge3
BACK