Re: Bug#1142348: ITP: proftpd-mod-procfs -- ProFTPD module mod_procfs

Preuße, Hilmar <[email protected]> Sat, 18 Jul 2026 12:20:18 +0200
Newsgroups gmane.linux.debian.devel.general
Message-ID <[email protected]>
Am 18.07.2026 um 11:15 schrieb Bastien Roucaries:
> Le samedi 18 juillet 2026, 11:11:07 heure d’été d’Europe centrale Hilmar Preusse a écrit :

Hello,

>> Upstream refuses to solve CVE-2026-35025 by doing code changes. Instead
>> it is suggested to deny access to the /proc file system. This is exactly,
>> what is done by that module.
> 
> Why does we could not use systemd restriction ?
> 
According to upstream one could also use PathDenyFilter to deny access 
to that path:

http://www.proftpd.org/docs/modules/mod_core.html#PathDenyFilter

This module is just an offer to end users to address this specific issue.

Hilmar
-- 
sigfault
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQRKnq6Z0VRDf4bMmAn98EQ6ARgcNAUCaltTYgUDAAAAAAAKCRD98EQ6ARgcNF+N
AQC1AwVaJZhaZj/0LIebkDNAouyGSfsy0vHwyUUr9+SzQgEApdcwJPf7ECqdwcT18S7x9uuu+hkc
Ekcp2GlTrw5OPwM=
=EXM9
-----END PGP SIGNATURE-----