This update addresses CVE-2009-3555 (SSL/TLS renegotiation vulnerability), mitigating the problem by refusing all client-initiated SSL/TLS session renegotiations.
This update to the latest maintenance release also fixes a number of bugs recorded in the proftpd bug tracker:
- SSL/TLS renegotiation vulnerability (CVE-2009-3555, bug 3324)
- Failed database transaction can cause mod_quotatab to loop (bug 3228)
- Segfault in mod_wrap (bug 3332)
- <Directory> sections can have <Limit> problems (bug 3337)
- mod_wrap2 segfaults when a valid user retries the USER command (bug 3341)
- modauthfile handles 'getgroups' request incorrectly (bug 3347)
- Segfault caused by scrubbing zero-length portion of memory (bug 3350)
- Lack of PID protection in ScoreboardFile (bug 3370)
- Crash when retrying a failed login with mod_radius being used (bug 3372)
- RADIUS authentication broken on 64-bit platforms (bug 3381)
- SIGHUP eventually causes certain DSO modules to segfault (bug 3387)
Finally, the behaviour of the MLSD FTP command (used in many modern FTP clients to list directories) is fixed for the case when the FTP server's configuration disallows its usage (using a <Limit> clause) in some but not all places (#544002).
Please login to add feedback.