vulnerable version of proftpd

Bug #515486 reported by Daniele Daccurso
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
proftpd (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Binary package hint: proftpd

Hello,

In Ubuntu 8.04 LTS the most recent version of proftpd which is aviable to install via apt-get is "1.3.1-1", the problem is, that it's vulnerable, as you can see after a few seconds of google search :

http://www.google.de/search?rlz=1C1CHNG_deDE364DE364&sourceid=chrome&ie=UTF-8&q=exploit+proftpd+1.3.1

The 1.3.1 is from october 2007, the 1.3.3 is still a relase candidate but the 1.3.2 is final and there has been a security fix as you can see in the relase notes :

http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c

--- QUOTE ---
1.3.2 (stable)
---------------

  + Security fixes

    Fixed encoding-dependent SQL injection vulnerability in mod_sql_mysql
    and mod_sql_postgres modules.

--- END QUOTE ---

greets from germany :)

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in proftpd (Ubuntu):
status: New → Confirmed
visibility: private → public
Changed in proftpd (Ubuntu):
importance: Undecided → Medium
Revision history for this message
Chris Vigelius (chris-vigelius) wrote :

I don't know if this helps, but since 1.3.1 had some other problems too, I've made a hardy PPA for 1.3.2 (which also has the fix for the remote vulnerability described in http://bugs.proftpd.org/show_bug.cgi?id=3521)

ppa is here: https://launchpad.net/~chris-vigelius/+archive/chrisv

Revision history for this message
Amr Ibrahim (amribrahim1987) wrote :

In the future, please use 'ubuntu-bug package-name' to report Ubuntu bugs.
https://help.ubuntu.com/community/ReportingBugs

You have reported a bug in a non-existent package in Ubuntu archives since 2007. No developer will see this bug report because simply the package does not exist any more.

Changed in proftpd (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.