Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 10 ProFTPD 1.3.1-8 Critical: CSRF Command Execution Fix

fedora
Calendar Grey January 7, 2009
Dist Fedora Esm H88
ProFTPD patch enhances protection against CSRF vulnerabilities while addressing SSL termination issues in Fedora 10. Ensure safety with the newest updates.
This update fixes a security issue where an attacker could conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands

Summary

ProFTPD is an enhanced FTP server with a focus toward simplicity, security,

and ease of configuration. It features a very Apache-like configuration

syntax, and a highly customizable server infrastructure, including support for

multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory

visibility.

This package defaults to the standalone behaviour of ProFTPD, but all the

needed scripts to have it run by xinetd instead are included.

This update fixes a security issue where an attacker could conduct cross-site

request forgery (CSRF) attacks and execute arbitrary FTP commands. It also fixes

some SSL shutdown issues seen with certain clients.

* Fri Jan 2 2009 Matthias Saou 1.3.1-8

- Update default configuration to have a lit of available modules and more

example configuration for them.

- Include patches to fix TLS issues (#457280).

* Fri Jan 2 2009 Matthias Saou 1.3.1-7

- Add Debian patch to fix CSRF vulnerability (#464127, upstream #3115).

[ 1 ] Bug #464127 - CVE-2008-4242 proftpd CSRF attack

https://bugzilla.redhat.com/show_bug.cgi?id=464127

su -c 'yum update proftpd' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 10
Version: 1.3.1
Release: 8.fc10
Summary: Flexible, stable and highly-configurable FTP server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here