LWN.net Logo

proftpd-dfsg: certificate spoofing

Package(s):proftpd-dfsg CVE #(s):CVE-2009-3639
Created:November 2, 2009 Updated:December 28, 2009
Description:

From the Debian advisory:

It has been discovered that proftpd-dfsg, a virtual-hosting FTP daemon, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, when the dNSNameRequired TLS option is enabled.

Alerts:
Fedora FEDORA-2009-11649 2009-11-18
Debian DSA-1925-1 2009-10-31
Fedora FEDORA-2009-11666 2009-11-18

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds