Description of problem: vsftpd's default config identifies the name of the daemon. How reproducible: very Steps to Reproduce: 1. edit vsftpd.conf 2. ftpd_banner variable is commented out, causing condition Additional info: ftpd_banner= should be set with a single space after the equal sign, eliminating any name identification for daemon.
Many daemons identify themselves and whilst it is good security practise to remove idenitification history has shown that the majority of worms and exploits simply ignore any identification when trying to exploit a particular vulnerability. I'm moving this to being an enhancement severity.
I doubt we'd change this local to Red Hat; perhaps you can convince the upstream vsftpd package to change this behavior?