Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1182230

Bug#1060767: bookworm-pu: package proftpd-mod-proxy/0.9.2-1+deb12u1

From Hilmar Preusse <hille42@web.de>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#1060767: bookworm-pu: package proftpd-mod-proxy/0.9.2-1+deb12u1
Date 2024-01-13 22:10 +0100
Message-ID <HVTqp-2SUT-1@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: proftpd-mod-proxy@packages.debian.org
Control: affects -1 + src:proftpd-mod-proxy

[ Reason ]
The version currently in Debian stable suffers from the CVE-2023-48795
(Terrapin attack) security issue.

[ Impact ]
Proftp further suffers from the described security issues.

[ Tests ]
The current change is directly copied from the upstream git repo. They have a
test suite for that package, it is not yet activated in Debian.

[ Checklist ]
  [X] *all* changes are documented in the d/changelog
  [X] I reviewed all changes and I approve them
  [X] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
Patch for CVE-2023-48795 (copied from upstream's repo)

[ Other info ]
The debdiff is available here:
https://release.debian.org/proposed-updates/bookworm_diffs/proftpd-mod-proxy_0.9.2-1+deb12u1.debdiff

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1060767: bookworm-pu: package proftpd-mod-proxy/0.9.2-1+deb12u1 Hilmar Preusse <hille42@web.de> - 2024-01-13 22:10 +0100
  Bug#1060767: proftpd-mod-proxy 0.9.2-1+deb12u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2024-01-20 17:40 +0100

csiph-web