Debian alert DLA-1753-2 (proftpd-dfsg)
From: | Markus Koschany <apo@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 1753-2] proftpd-dfsg regression update | |
Date: | Wed, 1 May 2019 17:34:14 +0200 | |
Message-ID: | <b0d8ac02-1ff0-d854-6b3b-ffada1518f78@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : proftpd-dfsg Version : 1.3.5e+r1.3.5-2+deb8u1 CVE ID : not available Debian Bug : 923926 926719 The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719). This update reverts to upstream version 1.3.5 again since even the latest upstream release 1.3.6 is still affected by different sftp related bugs (#927270). All fixes for the memory leaks were backported separately now. For Debian 8 "Jessie", this problem has been fixed in version 1.3.5e+r1.3.5-2+deb8u1. We recommend that you upgrade your proftpd-dfsg packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlzJvHVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeQ8LA/+IZfJGV06mpvPCosgq3OpiDB70WyODFDMkHSvGrlIOSRIXMmPImt/7bVR brSH91449KQZDk7+jU8NnFym6PAZOKOeifDV+83t2jc4KaAFo+albeW5ydvt5Gxi GQUFAFJv3s+72HGdcZ5cMzgjUsGCXXB9qtUJ8mIPOOiBRayDdtmZjLoO8Bwez9G0 xTGLyJZjAekO+JRDpDMCBwtkLwwYFE83lNJ/PsElteEFdngKyE+4IKcpYQjehoy9 y7LBD9gNmlsRTuvsojCB/y58jP3fg2It6aoGYMnEczkHwUu88v1xt+v4E9QLIutV hy9qzgJFzsqkgDamjpI0qoeEG+Sn2zWNNBMg4gidylwy/IlOR6MbvUHsCOIVVsRi OlZHBdgQdTIsrJVBPxU2+XBCAD9Mw1eQP+QRrDasENikHGefsh0jVGkdp9Adt1vn aXNE+nGCq3xoHBGN5/jKJnTP1s1BsLsRnXJuYxKPxmYwn6Vz1LsXItELsdwXtepL uB4zChv1LfGr4YJPLjft3mig+k8hK+LJO7UTxgLruDoF5+i+I+siVxC497BlGqlc sXf18ALhD7t3uUnbKDPTHkFgDNI7riXe6CLr6qCJyhb+mG1eB64+4f6bXKQRI+FI Trl2rppyLzj8V2+TuPwl8cXbP6bmn9YasJewEGaUGF1184qafNo= =bmLQ -----END PGP SIGNATURE-----