MGASA-2021-0434 - Updated proftpd packages fix security vulnerability

Publication date: 23 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0434.html
Type: security
Affected Mageia releases: 8

Fixes memory disclosure to RADIUS servers by mod_radius.

Ftp clients like filezilla fail to detect locale with in log :
"Status: Server does not support non-ASCII characters."

This comes from proftpd MultilineRFC2228 directive enabled by default.

Without this directive  Filezilla is able to enable utf8 options
correctly.

Fixed by disabling MultilineRFC2228 directive.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29449
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/K3JL66LCDUIASS4TM7SY6R2D7W2WBXUE/
- https://bugzilla.redhat.com/show_bug.cgi?id=2001690
- https://github.com/proftpd/proftpd/issues/1085

SRPMS:
- 8/core/proftpd-1.3.7a-3.1.mga8

Mageia 2021-0434: proftpd security update

Fixes memory disclosure to RADIUS servers by mod_radius

Summary

Fixes memory disclosure to RADIUS servers by mod_radius. Ftp clients like filezilla fail to detect locale with in log : "Status: Server does not support non-ASCII characters."

References

- https://bugs.mageia.org/show_bug.cgi?id=29449

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/K3JL66LCDUIASS4TM7SY6R2D7W2WBXUE/

- https://bugzilla.redhat.com/show_bug.cgi?id=2001690

- https://github.com/proftpd/proftpd/issues/1085

Resolution

MGASA-2021-0434 - Updated proftpd packages fix security vulnerability

SRPMS

- 8/core/proftpd-1.3.7a-3.1.mga8

Severity
Publication date: 23 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0434.html
Type: security

Related News