| From: |
| Meltem Parmaksız <meltem@pardus.org.tr> |
| To: |
| pardus-security@pardus.org.tr |
| Subject: |
| [Pardus-security] [PLSA 2011-91] lftp: MITM |
| Date: |
| Thu, 7 Jul 2011 09:35:25 +0300 |
| Message-ID: |
| <201107070935.25782.meltem@pardus.org.tr> |
| Archive-link: |
| Article, Thread
|
------------------------------------------------------------------------
Pardus Linux Security Advisory 2011-91 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2011-07-06
Type: Remote
------------------------------------------------------------------------
Summary
=======
A vulnerability has been fixed in lftp.
Description
===========
lftp up to and including version 4.1.3 has an option
"ssl:verify-certificate" which unfortunatly defaults to "no". Ie no
certificate checks. Moreover, when compiled with openssl rather than
gnutls lftp does not turn off SSLv2 (bad for openssl pre 1.0) and
lacks code to actually verify the hostname. Ie it's prone to MITM.
Affected packages:
Pardus 2009:
lftp, all before 4.2.2-6-6
Resolution
==========
There are update(s) for lftp. You can update them via Package Manager or
with a single command from console:
pisi up lftp
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=16993
------------------------------------------------------------------------
_______________________________________________
Pardus-Security mailing list
Pardus-Security@pardus.org.tr
http://liste.pardus.org.tr/mailman/listinfo/pardus-security
(
Log in to post comments)