LWN.net Logo

Pardus alert 2011-91 (lftp)

From:  Meltem Parmaksız <meltem@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2011-91] lftp: MITM
Date:  Thu, 7 Jul 2011 09:35:25 +0300
Message-ID:  <201107070935.25782.meltem@pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2011-91 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2011-07-06 Type: Remote ------------------------------------------------------------------------ Summary ======= A vulnerability has been fixed in lftp. Description =========== lftp up to and including version 4.1.3 has an option "ssl:verify-certificate" which unfortunatly defaults to "no". Ie no certificate checks. Moreover, when compiled with openssl rather than gnutls lftp does not turn off SSLv2 (bad for openssl pre 1.0) and lacks code to actually verify the hostname. Ie it's prone to MITM. Affected packages: Pardus 2009: lftp, all before 4.2.2-6-6 Resolution ========== There are update(s) for lftp. You can update them via Package Manager or with a single command from console: pisi up lftp References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=16993 ------------------------------------------------------------------------ _______________________________________________ Pardus-Security mailing list Pardus-Security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds