obsolete

proftpd-1.3.5e-1.el7

FEDORA-EPEL-2017-b9db4ff3ec created by pghmcfc 8 years ago for Fedora EPEL 7

Current upstream maintenance release for the 1.3.5 series.

Includes fix for CVE-2017-7418, where not all path elements were checked for symlinks when using a chroot, so attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link.

This update has been submitted for testing by pghmcfc.

8 years ago

This update has been pushed to testing.

8 years ago

This update has reached 14 days in testing and can be pushed to stable now if the maintainer wishes

8 years ago

This update has been obsoleted by proftpd-1.3.5e-2.el7.

8 years ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-1
Stable by Karma
disabled
Stable by Time
disabled
Thresholds
Minimum Karma
+1
Minimum Testing
7 days
Dates
submitted
8 years ago
in testing
8 years ago
BZ#1439693 CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass
0
0
BZ#1439696 CVE-2017-7418 proftpd: AllowChrootSymlinks control bypass [epel-all]
0
0

Automated Test Results