MGASA-2019-0314

Source
https://advisories.mageia.org/MGASA-2019-0314.html
Import Source
https://advisories.mageia.org/MGASA-2019-0314.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0314
Related
Published
2019-11-07T23:36:48Z
Modified
2019-11-07T22:22:42Z
Summary
Updated proftpd packages fix security vulnerabilities
Details

Updated proftpd package fixes security vulnerabilities:

It was discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands (CVE-2019-12815).

It was discovered that due to incorrect handling of overly long commands, a remote unauthenticated user could trigger a denial-of-service by reaching an endless loop (CVE-2019-18217).

References
Credits

Affected packages

Mageia:7 / proftpd

Package

Name
proftpd
Purl
pkg:rpm/mageia/proftpd?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.5e-4.1.mga7

Ecosystem specific

{
    "section": "core"
}