SHARE
Facebook X Pinterest WhatsApp

Debian Security Advisory: New version of proftpd released

Written By
thumbnail
Web Webster
Web Webster
Feb 12, 2001

Date: Sun, 11 Feb 2001 22:53:36 -0500 (EST)
From: Michael Stone mstone@osgiliath.ddts.net

To: debian-security-announce@lists.debian.org
Subject: [SECURITY] [DSA-029-1] New version of proftpd released


Debian Security Advisory DSA-029-1                                      security@debian.org
http://www.debian.org/security/                                   Michael Stone 
February 11, 2001


Package: proftpd
Vulnerability: remote DOS & potential buffer overflow
Debian-specific: no

The following problems have been reported for the version of
proftpd in Debian 2.2 (potato):

1. There is a memory leak in the SIZE command which can result
in a denial of service, as reported by Wojciech Purczynski. This is
only a problem if proftpd cannot write to its scoreboard file; the
default configuration of proftpd in Debian is not vulnerable.

2. A similar memory leak affects the USER command, also as
reported by Wojciech Purczynski. The proftpd in Debian 2.2 is
susceptible to this vulnerability; an attacker can cause the
proftpd daemon to crash by exhausting its available memory.

3. There were some format string vulnerabilities reported by
Przemyslaw Frasunek. These are not known to have exploits, but have
been corrected as a precaution.

All three of the above vulnerabilities have been corrected in
proftpd-1.2.0pre10-2potato1. We recommend you upgrade your proftpd
package immediately.

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 2.2 alias potato


Potato was released for the alpha, arm, i386, m68k, powerpc and
sparc architectures.

Source archives:

http://security.debian.org/debian-security/dists/stable/updates/main/source/proftpd_1.2.0pre10-2potato1.diff.gz

MD5 checksum: ac1f26e4effe5c6d46b9254b5edea94c


http://security.debian.org/debian-security/dists/stable/updates/main/source/proftpd_1.2.0pre10-2potato1.dsc

MD5 checksum: 305a6c3ba88afd493d94a3ecd8f92db1


http://security.debian.org/debian-security/dists/stable/updates/main/source/proftpd_1.2.0pre10.orig.tar.gz

MD5 checksum: a1c25e59bb4281e2f83000796dc52388

Alpha architecture:

http://security.debian.org/debian-security/dists/stable/updates/main/binary-alpha/proftpd_1.2.0pre10-2potato1_alpha.deb

MD5 checksum: 9f1deb1050544c51de8a5be6e1134d05

ARM architecture:

http://security.debian.org/debian-security/dists/stable/updates/main/binary-arm/proftpd_1.2.0pre10-2potato1_arm.deb

MD5 checksum: 7226be3c206b287959357e3186593a71

Intel ia32 architecture:

http://security.debian.org/debian-security/dists/stable/updates/main/binary-i386/proftpd_1.2.0pre10-2potato1_i386.deb

MD5 checksum: 13f9f7bfb44c09dc1a69fb678aad5f2c

Motorola 680×0 architecture:
Not yet available.

PowerPC architecture:

http://security.debian.org/debian-security/dists/stable/updates/main/binary-powerpc/proftpd_1.2.0pre10-2potato1_powerpc.deb

MD5 checksum: 9c03031c8de3da26686605fe7875b8b3

Sun Sparc architecture:

http://security.debian.org/debian-security/dists/stable/updates/main/binary-sparc/proftpd_1.2.0pre10-2potato1_sparc.deb

MD5 checksum: 1a17e4a65319645513ce86c174342d0e

For not yet released architectures please refer to the
appropriate directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/
.


For apt-get: deb http://security.debian.org/
stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security
dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>’ and http://packages.debian.org/<pkg>

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

A Thorough Approach to Improve the Privacy and Security of Your Linux PC
Damien
Oct 24, 2024
Several Russian Maintainers Removed From Linux Kernel Due To Compliance Concerns
Senthil Kumar
Oct 23, 2024
OpenSSH Splits Again: New Authentication Binary Unveiled
Bobby Borisov
Oct 16, 2024
13 Best Free and Open Source Anti-Malware Tools
webmaster
Oct 14, 2024
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.