Security flaw: The package configures pure-ftpd to start automatically without informing the user/admin.

Bug #1502687 reported by Vesa P.
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
pure-ftpd (Ubuntu)
New
Undecided
Unassigned

Bug Description

It seems to me that when pure-ftpd is installed, it is also configured to start automatically as part of the boot process. Now, this is a dangerous practice when the user/administrator is not informed about this.

I construe that the documentation that comes with the package comes from the developers of pure-ftpd, whereas the decision or code to automatically start pure-ftpd has been made by the creator of the package. Now, there are probably a number of approaches to fixing this bug, fox example:
 (1) Disabling auto-start by default,
 (2) adding documentation about configuration arrangements specific to this Ubuntu/Debian package of pure-ftpd,
 (3) showing some sort of an information window to inform the user/administrator that auto-starting has been enabled and how to disable it if desired.

I believe FTP servers are generally configured by the administrator before introducing to regular use, and therefore starting them automatically in a "plug-and-play" fashion is not of so much benefit. Anyway, the administrator must be informed, for sure, lest the FTP server go online unconfigured or half-configured.

Revision history for this message
Seth Arnold (seth-arnold) wrote : Bug is not a security issue

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

information type: Private Security → Public
Revision history for this message
Seth Arnold (seth-arnold) wrote :

For better or for worse, starting daemons at package install time is Debian tradition. (I thought it was Debian policy but I couldn't actually find any references there.)

It'd be best to report this bug to Debian; I think that has more chance of traction.

Thanks

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.