Re: [BLFS Trac] #23208: proftpd-1.3.9a

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23208: proftpd-1.3.9a
-------------------------+------------------------
 Reporter:  Bruce Dubbs  |       Owner:  blfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------
Changes (by Douglas R. Reno):

 * priority:  normal => high

Comment:

 This contains a fix for an SQL Injection vulnerability. I suspect most
 users of BLFS aren't affected, but better to be safe with these since
 there is a demonstration of remote code execution.
 https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce

 {{{
 1.3.9a
 ---------

   + Fix for SQL injection (CVE-2026-42167)
 }}}

 Rated as 8.1 High.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23208#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.