This update addresses a number of bugs affecting processing of CRLs in mod_tls, including possible null pointer dereferences and missing some checks. Thanks to Lionel Debroux for reporting them.
This update has been submitted for testing by pghmcfc.
BZ#1777975 CVE-2019-19269 proftpd: NULL pointer dereference when validating the certificate of a client connecting to the server
0
0
BZ#1777978 CVE-2019-19269 proftpd: NULL pointer dereference when validating the certificate of a client connecting to the server [epel-7]
0
0
BZ#1778222 CVE-2019-19272 proftpd: NULL pointer dereference in tls_verify_crl when validating the certificate of a client
0
0
BZ#1778226 CVE-2019-19272 proftpd: NULL pointer dereference in tls_verify_crl when validating the certificate of a client [epel-all]
0
0
BZ#1778231 CVE-2019-19271 proftpd: A wrong iteration variable, used when checking a client certificate against CRL entries, can cause some CRL entries to be ignored
0
0
BZ#1778233 CVE-2019-19271 proftpd: A wrong iteration variable, used when checking a client certificate against CRL entries, can cause some CRL entries to be ignored [epel-all]
0
0
BZ#1778258 CVE-2019-19270 proftpd: failure to check for the appropriate field of a CRL entry prevents some valid CRLs from being taken into account
0
0
BZ#1778261 CVE-2019-19270 proftpd: failure to check for the appropriate field of a CRL entry prevents some valid CRLs from being taken into account [epel-all]
This update has been submitted for testing by pghmcfc.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'ignored'.
pghmcfc edited this update.
pghmcfc edited this update.
pghmcfc edited this update.
This update has been pushed to testing.
This update can be pushed to stable now if the maintainer wishes
This update has been submitted for stable by bodhi.
This update has been pushed to stable.