MGASA-2020-0120 - Updated proftpd packages fix security vulnerability

Publication date: 06 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0120.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-9273

Updated proftpd packages fix security vulnerability:

Antonio Morales discovered an use-after-free flaw in the memory pool
allocator in ProFTPD. Interrupting current data transfers can corrupt
the ProFTPD memory pool, leading to denial of service, or potentially
the execution of arbitrary code (CVE-2020-9273).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26251
- https://www.debian.org/security/2020/dsa-4635
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9273

SRPMS:
- 7/core/proftpd-1.3.5e-4.3.mga7

Mageia 2020-0120: proftpd security update

Updated proftpd packages fix security vulnerability: Antonio Morales discovered an use-after-free flaw in the memory pool allocator in ProFTPD

Summary

Updated proftpd packages fix security vulnerability:
Antonio Morales discovered an use-after-free flaw in the memory pool allocator in ProFTPD. Interrupting current data transfers can corrupt the ProFTPD memory pool, leading to denial of service, or potentially the execution of arbitrary code (CVE-2020-9273).

References

- https://bugs.mageia.org/show_bug.cgi?id=26251

- https://www.debian.org/security/2020/dsa-4635

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9273

Resolution

MGASA-2020-0120 - Updated proftpd packages fix security vulnerability

SRPMS

- 7/core/proftpd-1.3.5e-4.3.mga7

Severity
Publication date: 06 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0120.html
Type: security
CVE: CVE-2020-9273

Related News