Re: [BLFS Trac] #23208: proftpd-1.3.9a

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23208: proftpd-1.3.9a
-------------------------+-------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Changes (by Joe Locash):

 * owner:  Joe Locash => SecurityAdvisory
 * status:  assigned => new

Comment:

 {{{
 1.3.9a - Released 27-Apr-2026
 --------------------------------
 - Issue 1886 - SCP transfers fail for files with spaces in their names.
 - Issue 1898 - LDAPDefaultGID ignored since 1.3.9.
 - Bug 4512 - Compilation of mod_wrap2 fails when the --enable-wrapper-
 options
   configure option is used.
 - Issue 1904 - mod_sftp fails to parse authorized user/host public keys
 with
   CRLF line endings.
 - Issue 1896 - Uploads using MODE Z sometimes result in corrupted files or
   broken transfers.
 - Issue 1911 - Remove usage of the deprecated MySQL_OPT_RECONNECT option
 for
   newer MySQL versions.
 - Issue 340 - Update usage of MySQL API for SSL/TLS connections to server.
 - Issue 1959 - mod_sftp leaks file descriptor when reading SFTPHostKey
 file.
 - Issue 1964 - Large/slow SCP downloads could be unnecessarily truncated
 by
   TimeoutStalled.
 - Issue 1960 - Handling of CRLs in mod_tls is incorrect, leading to
 confusing
   errors.
 - Issue 1963 - Resumed SSL_SESSION management in mod_tls leads to memory
   growth, infinite loop using newer OpenSSL versions.
 - Issue 1984 - mod_quotatab_ldap interactions can lead to segfault due to
   stale pointer.
 - Issue 2003 - RNTO before authentication leads to out-of-order response
 codes.
 - Issue 2009 - MaxLoginAttemptsFromUser event never triggers in mod_ban
 for
   SFTP sessions.
 - Issue 2019 - Using toupper(3) on non-ASCII FTP command bytes may cause
   remote DoS.
 - Issue 2020 - Out-of-bounds single byte read when FTP command input
 buffer
   starts with LF.
 - Issue 2030 - FTP command LIST/NLST -B can cause buffer overflow when
 listing
   certain crafted filenames.
 - Issue 2043 - Memory exhaustion with mod_log_forensic when downloading
 very
   large files via SFTP.
 - Issue 2046 - Setting process groups during authentication crashes when
 using
   mod_radius and <IfGroup>.
 - Issue 2052 - SQL injection possible via mod_sql because of
 is_escaped_text()
   logic error (CVE-2026-42167).
 }}}
 Fixed at 5881ce7bd5. Leaving open for SA.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23208#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.