LWN.net Logo

Fedora alert FEDORA-2013-0483 (proftpd)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: proftpd-1.3.4b-5.fc17
Date:  Wed, 30 Jan 2013 00:59:00 +0000
Message-ID:  <20130130005858.7168621B73@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-0483 2013-01-09 08:17:43 -------------------------------------------------------------------------------- Name : proftpd Product : Fedora 17 Version : 1.3.4b Release : 5.fc17 URL : http://www.proftpd.org/ Summary : Flexible, stable and highly-configurable FTP server Description : ProFTPD is an enhanced FTP server with a focus toward simplicity, security, and ease of configuration. It features a very Apache-like configuration syntax, and a highly customizable server infrastructure, including support for multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory visibility. This package defaults to the standalone behavior of ProFTPD, but all the needed scripts to have it run by xinetd instead are included. -------------------------------------------------------------------------------- Update Information: Jann Horn reported that there is a possible race condition in the handling of the MKD/XMKD FTP commands, when the UserOwner directive is involved, and the attacker is on the same physical machine as a running proftpd. This race applies to mod_sftp and the handling of the MKDIR SFTP request as well. Note that using the DefaultRoot directive to restrict sessions mitigates this attack, since the symlinks created by the local attacker will point outside of the chroot(2) area within the FTP session, and thus the ownership change will fail. The default configuration in Fedora applies the DefaultRoot directive to all users except "adm". The upstream reference for this issue is: http://bugs.proftpd.org/show_bug.cgi?id=3841 This update includes upstream's backport to proftpd 1.3.4 of the fix for this issue. -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 16 2013 Paul Howarth <paul@city-fan.org> 1.3.4b-5 - Update patch for CVE-2012-6095 to cover vroot cases * Mon Jan 7 2013 Paul Howarth <paul@city-fan.org> 1.3.4b-4 - Fix possible symlink race when applying UserOwner to newly created directory (CVE-2012-6095, #892715, http://bugs.proftpd.org/show_bug.cgi?id=3841) * Sat Sep 22 2012 Remi Collet <remi@fedoraproject.org> 1.3.4b-3 - Rebuild against libmemcached.so.11 without SASL * Thu Aug 30 2012 Paul Howarth <paul@city-fan.org> 1.3.4b-2 - Add support for systemd presets in Fedora 18+ (#850281) * Wed Aug 1 2012 Paul Howarth <paul@city-fan.org> 1.3.4b-1 - Update to 1.3.4b - Fixed mod_ldap segfault on login when LDAPUsers with no filters used - Fixed sporadic SFTP upload issues for large files - Fixed SSH2 handling for some clients (e.g. OpenVMS) - New FactsOptions directive; see doc/modules/mod_facts.html#FactsOptions - Fixed build errors on Tru64, AIX, Cygwin - Lots of bugs fixed - see NEWS for details - No bzipped tarball release this time, so revert to gzipped one - Drop patches for fixes included in upstream release * Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> 1.3.4a-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Tue Jul 3 2012 Paul Howarth <paul@city-fan.org> 1.3.4a-10 - Move tmpfiles.d file from %{_sysconfdir} to %{_prefix}/lib * Sat Apr 21 2012 Paul Howarth <paul@city-fan.org> 1.3.4a-9 - Rebuild for new libmemcached in Rawhide -------------------------------------------------------------------------------- References: [ 1 ] Bug #892715 - CVE-2012-6095 proftpd: Symlink race condition when applying UserOwner to a newly (ProFTPD) created directory https://bugzilla.redhat.com/show_bug.cgi?id=892715 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update proftpd' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds