Linux.com

Home DistributionCentral Linux Security Debian Security Advisory 1925 proftpd-dfsg - insufficient input validation

Debian Security Advisory 1925 proftpd-dfsg - insufficient input validation


Article Source Debian Security Advisories
October 30, 2009, 5:00 pm

It has been discovered that proftpd-dfsg, a virtual-hosting FTP daemon, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, when the dNSNameRequired TLS option is enabled.

For the stable distribution (lenny), this problem has been fixed in version 1.3.1-17lenny4.

For the oldstable distribution (etch), this problem has been fixed in version 1.3.0-19etch3.

Binaries for the amd64 architecture will be released once they are available...

Read More

Comments (0)Add Comment

Write comment
You must be logged in to post a comment. Please register if you do not have an account yet.

busy
 
Become a Linux Foundation Member

Who we are ?

The Linux Foundation is a non-profit consortium dedicated to the growth of Linux.

More About the foundation...

Frequent Questions

Join / Members / Staff / Board