Perform unidirectional SSL/TLS shutdown on data connections

Bug #514481 reported by cdenley
270
This bug affects 3 people
Affects Status Importance Assigned to Milestone
proftpd (Ubuntu)
Confirmed
Undecided
Unassigned
Nominated for Hardy by cdenley

Bug Description

Binary package hint: proftpd

Recent versions of FileZilla cannot establish an encrypted data connection to ProFTPD <=1.3.2rc1 since they now strictly enforce their interpretation of the RFC standard since they consider non-compliant servers, such as hardy's proftpd, a security risk.

"Closing the data connection for the transfer connection without an orderly SSL/TLS shutdown violates the specifications. Furthermore, not performing the shutdown is indistinguishable from an attacker sending spoofed FIN TCP packets to the server, leading to truncated, yet apparently complete, successful transfers."

http://forum.filezilla-project.org/viewtopic.php?f=2&t=7688
http://bugs.proftpd.org/show_bug.cgi?id=3094

visibility: private → public
Changed in proftpd (Ubuntu):
status: New → Confirmed
Revision history for this message
Martin Henze (martin-henze) wrote :

This is a real issue in Hardy. Would love if someone could port the bugfix to the hardy package.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.