Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 2019-0314: ProFTPD Security Advisory of Critical Importance

mageia
Calendar Grey November 7, 2019
Dist Mageia Esm H88
Recent updates to ProFTPD packages rectify severe security vulnerabilities within Mageia distributions, associated with various CVE identifiers.
Updated proftpd package fixes security vulnerabilities: It was discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation f...

Summary

Updated proftpd package fixes security vulnerabilities:
It was discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands (CVE-2019-12815).
It was discovered that due to incorrect handling of overly long commands, a remote unauthenticated user could trigger a denial-of-service by reaching an endless loop (CVE-2019-18217).

References

- https://bugs.mageia.org/show_bug.cgi?id=25287

- https://www.cve.org/CVERecord?id=CVE-2019-12815

- https://www.cve.org/CVERecord?id=CVE-2019-12817

Resolution

SRPMS

- 7/core/proftpd-1.3.5e-4.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 07 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0314.html
Type: security
CVE: CVE-2019-12815, CVE-2019-12817

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here