MGASA-2015-0485
Dashboard / Vulnerabilities / MGASA-2015-0485
MGASA-2015-0485
Summary: Updated proftpd packages fix security vulnerabilities
Details: Updated proftpd packages fix security vulnerability: Part of the SFTP handshake involves "extensions", which are key/value pairs, comprised of strings. In SSH, strings are encoded for network transport as a 32-bit length, followed by the bytes. The mod_sftp module currently places no bounds/length limitations when reading these SFTP extension key/value data from the network. A malicious attacker might attempt to encode large values, and allocate more memory than is necessary, causing excessive resource usage or the FTP daemon to crash (proftpd#4210). This update also includes a fix for a crash in mod_lang (proftpd#4206).
References: https://advisories.mageia.org/MGASA-2015-0485.html, https://bugs.mageia.org/show_bug.cgi?id=17336, http://bugs.proftpd.org/show_bug.cgi?id=4206, http://bugs.proftpd.org/show_bug.cgi?id=4210, https://lists.fedoraproject.org/pipermail/package-announce/2015-November/171090.html, https://lists.fedoraproject.org/pipermail/package-announce/2015-December/173656.html
Affected packages
Package
Name: proftpd
Purl: pkg:rpm/mageia/proftpd?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
