From owner-doc-jp@jp.freebsd.org  Thu Sep  9 23:00:05 1999
Received: (from daemon@localhost)
	by castle.jp.freebsd.org (8.9.3+3.2W/8.7.3) id XAA47914;
	Thu, 9 Sep 1999 23:00:05 +0900 (JST)
	(envelope-from owner-doc-jp@jp.FreeBSD.org)
Received: from mx.micon.co.jp (merry.micon.co.jp [210.226.150.226])
	by castle.jp.freebsd.org (8.9.3+3.2W/8.7.3) with ESMTP id XAA47909
	for <doc-jp@jp.freebsd.org>; Thu, 9 Sep 1999 23:00:02 +0900 (JST)
	(envelope-from sakauchi@micon.co.jp)
Received: from sam.micon.co.jp (sam.micon.co.jp [210.226.150.227]) by mx.micon.co.jp (8.8.5/CF-3.5W+01/21/98) with ESMTP id XAA29380 for <doc-jp@jp.freebsd.org>; Thu, 9 Sep 1999 23:00:00 +0900 (JST)
Message-Id: <199909091359.WAA00462@kid.micon.co.jp>
To: doc-jp@jp.freebsd.org
In-Reply-To: Your message of "Thu, 09 Sep 1999 21:44:57 +0900 (JST)"
References: <199909091244.VAA00695@splpe481.ccs.mt.nec.co.jp>
X-Mailer: Mew version 1.69 on Emacs 19.28.1 / Mule 2.3
Mime-Version: 1.0
Content-Type: Text/Plain; charset=iso-2022-jp
Content-Transfer-Encoding: 7bit
Date: Thu, 09 Sep 1999 22:59:59 +0900
From: Atushi Sakauchi <sakauchi@micon.co.jp>
Reply-To: doc-jp@jp.freebsd.org
Precedence: list
X-Distribute: distribute version 2.1 (Alpha) patchlevel 24e+990727
X-Sequence: doc-jp 6622
Subject: [doc-jp 6622] Re: ANNOUNCE: FreeBSD Security Advisory:
 FreeBSD-SA-99:03.ftpd
Errors-To: owner-doc-jp@jp.freebsd.org
Sender: owner-doc-jp@jp.freebsd.org
X-Originator: sakauchi@micon.co.jp

$B:dFb$G$9!#(B

$B$3$,$5$s!'(B
> $B$3$l$OLu$7$?J}$,$h$5$=$&$G$O$"$k!D(B $B$,!"Fq$7$$!#(B

$B$&!<$s!D(B $B!VCm0U!W0J30$O$=$N$^$^!D(B

> $B$G$b!"$3$N(B advisory $B$O(B ports $B$NOC$J$s$G!"(BFreeBSD $B8GM-$NLdBj$@$h$J$!!#(B
> $B$=$&$8$c$J$$$J$i!"(BWU-FTPD $B$O%*%j%8%J%k$N%Q%C%A$O=P$F$$$k$s$G!"%Q%C%A$O(B
> $B$"$j$K$J$k!#$J$s$+@09g@-$H$$$&$+0l4S@-$,%$%^%$%A$J5$$,$9$k!#(B

$B;d$b5$$K$J$C$?$N$GLuJ8$NA0$K@bL@$rDI2C$7$^$7$?!#(B

---$B$3$3$+$i(B
  $B$3$N%a!<%k$O(B announce-jp $B$KN.$l$?(B

Subject: ANNOUNCE: FreeBSD Security Advisory: FreeBSD-SA-99:03.ftpd
From: FreeBSD Security Officer <security-officer@freebsd.org>
Date: Tue, 7 Sep 1999 10:20:19 -0600 (MDT)
Message-Id: <199909071620.KAA13314@harmony.village.org>

$B$rF|K\8lLu$7$?$b$N$G$9(B.
  $B86J8$O(B PGP $B=pL>$5$l$F$$$^$9$,(B, $B$3$NF|K\8lLu$O(B PGP $B=pL>$5$l$F$$$^$;$s(B. 
$B%Q%C%AEy$NFbMF$,2~cb$5$l$F$$$J$$$3$H$r3NG'$9$k$?$a$K(B PGP $B$N%A%'%C%/$r9T(B
$B$J$&$K$O86J8$r;2>H$7$F$/$@$5$$(B. 
  $BF|K\8lLu$K$D$$$F$N$*Ld$$9g$o$;$O(B doc-jp@jp.freebsd.org $B$^$G(B
$B$*4j$$$7$^$9(B. 

  $B$J$*(B, $BK\J8Cf$N!V%Q%C%A(B: $B$J$7!W$O(B FreeBSD, Inc. $B$,(B Ports $B$KBP$9$k%Q%C(B
$B%A$rDs6!$7$J$$$H$$$&0UL#$G$"$j(B, WU-FTPD $B3+H/%0%k!<%W$O%Q%C%A$r8x3+$7$F(B
$B$$$^$9(B. 

                         $BK]Lu(B : $B:dFbFX(B <sakauchi@micon.co.jp>
                                $B$3$,$h$&$$$A$m$&(B <y-koga@jp.freebsd.org>
=============================================================================
FreeBSD-SA-99:03                                            Security Advisory
                                                                FreeBSD, Inc.

$B%H%T%C%/(B:             Two ftp daemons in ports vulnerable to attack.

$B%+%F%4%j!<(B:           ports
$B%b%8%e!<%k(B:           wu-ftpd $B$*$h$S(B proftpd
$B9pCNF|(B:               1999$BG/(B 9$B7n(B 5$BF|(B
$B1F6ABP>](B:             FreeBSD 3.2 ($B$*$h$S(B 3.2 $B0JA0$N%P!<%8%g%s(B)
		              $B=$@5$5$l$k0JA0$N(B FreeBSD-current.
$B=$@5:Q(B:               FreeBSD 3.3-RELEASE ($BLuCm(B: $BM=Dj(B)
		              1999$BG/(B 8$B7n(B 30$BF|0J9_$N(B FreeBSD-current
FreeBSD $B$@$1$NLdBj$+(B: $BH](B

$B%Q%C%A(B:               $B$J$7(B

I.   $BGX7J(B

WU-FTPD $B$H(B ProFTPD $B$K$O(B, $B%j%b!<%H$N%f!<%6!<$K(B root $B8"8B$rC%$o$l$k2DG=(B
$B@-$,$"$k$H$$$&<eE@$,$"$j$^$9(B. $B$I$A$i$bLdBj$N$"$kF1$8%3!<%I$r%Y!<%9$K$7(B
$B$F$$$k$N$G(B, $BF1$8LdBj$r;}$C$F$$$^$9(B. 

II.  $B2r@b(B

$B%j%b!<%H$N%f!<%6!<$,(B, $B%P%C%U%!%*!<%P!<%U%m!<$rMxMQ$7$F(B root $B8"8B$rF@$k(B
$B$3$H$,$G$-$^$9(B. 

III. $B1F6A(B

$B%j%b!<%H$N%f!<%6!<$,(B root $B8"8B$rF@$k$3$H$,$G$-$^$9(B. 

IV.  $BBP1~:v(B

$B%"%C%W%0%l!<%I$,40N;$9$k$^$G(B ftp $B%G!<%b%s$rDd;_$7$^$9(B. 

V.   $B2r7h:v(B

WU-FTPD $B$^$?$O(B ProFTPD $B$N(B ports $B$r(B, $B:G?7$N%P!<%8%g%s(B ( 1999$BG/(B8$B7n(B30$BF|0J(B
$B9_$N$b$N$K$D$$$F$O2r7h:Q$_(B ) $B$K%"%C%W%0%l!<%I$7$F$/$@$5$$(B. ports $B$rMx(B
$BMQ$7$F$$$J$$>l9g$O(B, $BLdBj$,$J$$%P!<%8%g%s$G$"$k$3$H$r3NG'$9$k$+(B, ports 
$B$rMxMQ$7$F%"%C%W%0%l!<%I$7$^$7$g$&(B. 

=============================================================================
FreeBSD, Inc.

Web Site:                       http://www.freebsd.org/
Confidential contacts:          security-officer@freebsd.org
Security notifications:         security-notifications@freebsd.org
Security public discussion:     freebsd-security@freebsd.org
PGP Key:                ftp://ftp.freebsd.org/pub/FreeBSD/CERT/public_key.asc

$BCm0U(B: $BK\J8=qCf$K%Q%C%A$,4^$^$l$F$$$k>l9g!"EE;R=pL>$d%a%$%i$N=hM}$GJQ99(B
      $B$5$l$k$?$a!"$=$N$^$^$G$O$-$A$s$HE,MQ$G$-$J$$$+$b$7$l$^$;$s!#I,MW(B
      $B$G$"$l$P!"K\J8=q$NKAF,$K5-:\$7$F$"$k(B URL $B$r;2>H$7$F%*%j%8%J%k$N(B
      $B%3%T!<$rF~<j$7$F$/$@$5$$!#(B
=============================================================================
