Bug#1142348: ITP: proftpd-mod-procfs -- ProFTPD module mod_procfs

Preuße, Hilmar <[email protected]>
Newsgroups gmane.linux.debian.devel.wnpp
Message-ID <33cefd57-bce4-4659-a040-a30e1ed0437e__20901.2918452331$1784370211$gmane$org@web.de>
Am 18.07.2026 um 11:15 schrieb Bastien Roucaries:
> Le samedi 18 juillet 2026, 11:11:07 heure d’été d’Europe centrale Hilmar Preusse a écrit :

Hello,

>> Upstream refuses to solve CVE-2026-35025 by doing code changes. Instead
>> it is suggested to deny access to the /proc file system. This is exactly,
>> what is done by that module.
> 
> Why does we could not use systemd restriction ?
> 
According to upstream one could also use PathDenyFilter to deny access 
to that path:

http://www.proftpd.org/docs/modules/mod_core.html#PathDenyFilter

This module is just an offer to end users to address this specific issue.

Hilmar
-- 
sigfault
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQRKnq6Z0VRDf4bMmAn98EQ6ARgcNAUCaltTYgUDAAAAAAAKCRD98EQ6ARgcNF+N
AQC1AwVaJZhaZj/0LIebkDNAouyGSfsy0vHwyUUr9+SzQgEApdcwJPf7ECqdwcT18S7x9uuu+hkc
Ekcp2GlTrw5OPwM=
=EXM9
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.