stable

pure-ftpd-1.0.30-1.el6

FEDORA-EPEL-2011-2804 created by lkundrak 12 years ago for Fedora EPEL 6

Wietse Venema and Victor Duchovni discovered and reported an issue that could lead to a potential information disclosure.

An unencrypted FTP command immediately following STARTTLS request would get buffered and processed prior to SSL/TLS handshake, resulting in potential authentication bypass in case a client certificate authentication was configured to provide user identity.

A report of similar issue that was originally discovered in Postfix MTA contains further technical details and discusses possible impact: http://www.postfix.org/CVE-2011-0411.html

Users of pure-ftpd are advised to install this updated package which contains a fix for the issue.

This update has been submitted for testing by lkundrak.

12 years ago

This update has been pushed to testing

12 years ago
User Icon lkundrak provided feedback 12 years ago
karma

This update has reached the stable karma threshold and will be pushed to the stable updates repository

12 years ago

This update has been pushed to stable

12 years ago

Please login to add feedback.

Metadata
Type
security
Karma
1
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
12 years ago
in testing
12 years ago
in stable
12 years ago
modified
12 years ago
BZ#683221 pure-ftpd: command injection during plaintext to TLS session switch
0
0

Automated Test Results