Re: Bug#1142348: ITP: proftpd-mod-procfs -- ProFTPD module mod_procfs
Preuße, Hilmar <[email protected]> Sat, 18 Jul 2026 12:20:18 +0200
| Newsgroups | gmane.linux.debian.devel.general |
|---|---|
| Message-ID | <[email protected]> |
Am 18.07.2026 um 11:15 schrieb Bastien Roucaries: > Le samedi 18 juillet 2026, 11:11:07 heure d’été d’Europe centrale Hilmar Preusse a écrit : Hello, >> Upstream refuses to solve CVE-2026-35025 by doing code changes. Instead >> it is suggested to deny access to the /proc file system. This is exactly, >> what is done by that module. > > Why does we could not use systemd restriction ? > According to upstream one could also use PathDenyFilter to deny access to that path: http://www.proftpd.org/docs/modules/mod_core.html#PathDenyFilter This module is just an offer to end users to address this specific issue. Hilmar -- sigfault
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQRKnq6Z0VRDf4bMmAn98EQ6ARgcNAUCaltTYgUDAAAAAAAKCRD98EQ6ARgcNF+N AQC1AwVaJZhaZj/0LIebkDNAouyGSfsy0vHwyUUr9+SzQgEApdcwJPf7ECqdwcT18S7x9uuu+hkc Ekcp2GlTrw5OPwM= =EXM9 -----END PGP SIGNATURE-----