| From: |
| updates@fedoraproject.org |
| To: |
| package-announce@lists.fedoraproject.org |
| Subject: |
| [SECURITY] Fedora 18 Update: proftpd-1.3.4b-5.fc18 |
| Date: |
| Wed, 30 Jan 2013 00:31:19 +0000 |
| Message-ID: |
| <20130130003116.E535E215FB@bastion01.phx2.fedoraproject.org> |
| Archive-link: |
| Article, Thread
|
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2013-0437
2013-01-08 20:08:55
--------------------------------------------------------------------------------
Name : proftpd
Product : Fedora 18
Version : 1.3.4b
Release : 5.fc18
URL : http://www.proftpd.org/
Summary : Flexible, stable and highly-configurable FTP server
Description :
ProFTPD is an enhanced FTP server with a focus toward simplicity, security,
and ease of configuration. It features a very Apache-like configuration
syntax, and a highly customizable server infrastructure, including support for
multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory
visibility.
This package defaults to the standalone behavior of ProFTPD, but all the
needed scripts to have it run by xinetd instead are included.
--------------------------------------------------------------------------------
Update Information:
Jann Horn reported that there is a possible race condition in the handling of the MKD/XMKD FTP
commands, when the UserOwner directive is involved, and the attacker is on the same physical
machine as a running proftpd. This race applies to mod_sftp and the handling of the MKDIR SFTP
request as well.
Note that using the DefaultRoot directive to restrict sessions mitigates this attack, since the
symlinks created by the local attacker will point outside of the chroot(2) area within the FTP
session, and thus the ownership change will fail. The default configuration in Fedora applies the
DefaultRoot directive to all users except "adm".
The upstream reference for this issue is:
http://bugs.proftpd.org/show_bug.cgi?id=3841
This update includes upstream's backport to proftpd 1.3.4 of the fix for this issue.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jan 16 2013 Paul Howarth <paul@city-fan.org> 1.3.4b-5
- Update patch for CVE-2012-6095 to cover vroot cases
* Mon Jan 7 2013 Paul Howarth <paul@city-fan.org> 1.3.4b-4
- Fix possible symlink race when applying UserOwner to newly created directory
(CVE-2012-6095, #892715, http://bugs.proftpd.org/show_bug.cgi?id=3841)
* Sat Sep 22 2012 Remi Collet <remi@fedoraproject.org> 1.3.4b-3
- Rebuild against libmemcached.so.11 without SASL
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #892715 - CVE-2012-6095 proftpd: Symlink race condition when applying UserOwner to a
newly (ProFTPD) created directory
https://bugzilla.redhat.com/show_bug.cgi?id=892715
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update proftpd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-...
(
Log in to post comments)