SUSE-SU-2022:3320-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3320-1
SUSE-SU-2022:3320-1
Summary: Security update for vsftpd
Details: This update for vsftpd fixes the following issues: - CVE-2021-3618: Enforced security checks against ALPACA attack (bsc#1187678, bsc#1187686, PM-3322). Bugfixes: - Fixed a seccomp failure in FIPS mode when SSL was enabled (bsc#1052900). - Allowed wait4() to be called so that the broker can wait for its child processes (bsc#1021387). - Allowed sendto() syscall when /dev/log support is enabled (bsc#786024).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223320-1/, https://bugzilla.suse.com/1021387, https://bugzilla.suse.com/1052900, https://bugzilla.suse.com/1187678, https://bugzilla.suse.com/1187686, https://bugzilla.suse.com/786024, https://www.suse.com/security/cve/CVE-2021-3618
Affected packages
Package
Name: vsftpd
Purl: pkg:rpm/suse/vsftpd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
