stable

pure-ftpd-1.0.30-1.el6

FEDORA-EPEL-2011-2804 created by lkundrak 13 years ago for Fedora EPEL 6

Wietse Venema and Victor Duchovni discovered and reported an issue that could lead to a potential information disclosure.

An unencrypted FTP command immediately following STARTTLS request would get buffered and processed prior to SSL/TLS handshake, resulting in potential authentication bypass in case a client certificate authentication was configured to provide user identity.

A report of similar issue that was originally discovered in Postfix MTA contains further technical details and discusses possible impact: http://www.postfix.org/CVE-2011-0411.html

Users of pure-ftpd are advised to install this updated package which contains a fix for the issue.

This update has been submitted for testing by lkundrak.

13 years ago

This update has been pushed to testing

13 years ago
User Icon lkundrak provided feedback 13 years ago
karma

This update has reached the stable karma threshold and will be pushed to the stable updates repository

13 years ago

This update has been pushed to stable

13 years ago

Please login to add feedback.

Metadata
Type
security
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
13 years ago
in testing
13 years ago
in stable
13 years ago
modified
13 years ago
BZ#683221 pure-ftpd: command injection during plaintext to TLS session switch
0
0

Automated Test Results