Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1289406

Bug#1133677: mod_radius: Message-Authenticator check always fails

Path csiph.com!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod
From Chris Hofstädtler <zeha@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#1133677: mod_radius: Message-Authenticator check always fails
Date Mon, 13 Apr 2026 16:20:01 +0200
Message-ID <MJqiR-eQGe-1@gated-at.bofh.it> (permalink)
X-Original-To Debian Bug Tracking System <submit@bugs.debian.org>
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Mon Apr 13 14:11:08 2026
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -1.699
Reply-To Chris Hofstädtler <zeha@debian.org>, 1133677@bugs.debian.org
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc pkg-proftpd-maintainers@alioth-lists.debian.net
X-Debian-Pr-Message report 1133677
X-Debian-Pr-Package proftpd-core
X-Debian-Pr-Keywords fixed-upstream upstream
X-Debian-Pr-Source proftpd-dfsg
MIME-Version 1.0
Content-Type text/plain; charset=utf-8
Content-Disposition inline
X-Reportbug-Version 13.2.0
X-Debian-User zeha
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1963767
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 20
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Mon, 13 Apr 2026 16:08:57 +0200
X-Original-Message-ID <adz4-a0Q5f2QGzUc@per.namespace.at>
Xref csiph.com linux.debian.bugs.dist:1289406

Show key headers only | View raw


Package: proftpd-core
Version: 1.3.8+dfsg-4+deb12u4
Severity: important
Tags: upstream fixed-upstream

Hi,

proftpd before commit 3cf5ad4b7e6df0e5a980aeab9021ef25c63dbfd6 fails 
to validate the RADIUS MAC signature, when talking to current 
FreeRADIUS (f.e. 3.2.7).

This is upstream bug https://github.com/proftpd/proftpd/issues/1840 
and fixed upstream in 1.3.8 in https://github.com/proftpd/proftpd/commit/3cf5ad4b7e6df0e5a980aeab9021ef25c63dbfd6

I've confirmed that applying the upstream patch to the Debian 
package fixes the problem. Please consider applying the patch and 
updating the version in oldstable.

Thanks,
Chris

Back to linux.debian.bugs.dist | Previous | Next | Find similar


Thread

Bug#1133677: mod_radius: Message-Authenticator check always fails Chris Hofstädtler <zeha@debian.org> - 2026-04-13 16:20 +0200

csiph-web