Updated proftpd packages fix security vulnerability:
Antonio Morales discovered an use-after-free flaw in the memory pool
allocator in ProFTPD. Interrupting current data transfers can corrupt
the ProFTPD memory pool, leading to denial of service, or potentially
the execution of arbitrary code (CVE-2020-9273).
- https://bugs.mageia.org/show_bug.cgi?id=26251
- https://lists.debian.org/debian-security-announce/2020/msg00038.html
- https://www.cve.org/CVERecord?id=CVE-2020-9273
- 7/core/proftpd-1.3.5e-4.3.mga7
Get the latest Linux and open source security news straight to your inbox.