Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 22 Pure-FTPd Security Update: FEDORA-2015-12961 DoS Fix

fedora
Calendar Grey August 12, 2015
Dist Fedora Esm H88
With recent DoS vulnerabilities in Pure-FTPd on Fedora 22, implementing vital security measures is crucial to reduce risks and prevent resource overload
* denial of service in glob_()

Summary

Pure-FTPd is a fast, production-quality, standard-comformant FTP server,

based upon Troll-FTPd. Unlike other popular FTP servers, it has no known

security flaw, it is really trivial to set up and it is especially designed

for modern Linux and FreeBSD kernels (setfsuid, sendfile, capabilities) .

Features include PAM support, IPv6, chroot()ed home directories, virtual

domains, built-in LS, anti-warez system, bandwidth throttling, FXP, bounded

ports for passive downloads, UL/DL ratios, native LDAP and SQL support,

Apache log files and more.

Rebuild switches:

--without ldap disable ldap support

--without mysql disable mysql support

--without pgsql disable postgresql support

--without extauth disable external authentication

--without tls disable SSL/TLS

Update Information:

* denial of service in glob_()

Change Log

* Wed Aug 5 2015 Jaromir Capik - 1.0.36-7 - Fixing denial of service in glob (#1233271)

References


[ 1 ] Bug #1233271 - pure-ftpd: denial of service in glob_() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1233271

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pure-ftpd' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: pure-ftpd
Product: Fedora 22
Version: 1.0.36
Release: 7.fc22
Summary: Lightweight, fast and secure FTP server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here