Fedora Linux 8776 Published by

A proftpd security update has been released for Fedora 34.



SECURITY: Fedora 34 Update: proftpd-1.3.7c-1.fc34


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-0a148b34a5
2021-09-08 15:05:54.167716
--------------------------------------------------------------------------------

Name : proftpd
Product : Fedora 34
Version : 1.3.7c
Release : 1.fc34
URL :   http://www.proftpd.org/
Summary : Flexible, stable and highly-configurable FTP server
Description :
ProFTPD is an enhanced FTP server with a focus toward simplicity, security,
and ease of configuration. It features a very Apache-like configuration
syntax, and a highly customizable server infrastructure, including support for
multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory
visibility.

This package defaults to the standalone behavior of ProFTPD, but all the
needed scripts to have it run by systemd instead are included.

--------------------------------------------------------------------------------
Update Information:

Cumulative bug-fix release from upstream.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Aug 31 2021 Paul Howarth - 1.3.7c-1
- Update to 1.3.7c
- Improve mod_tls log messages for unsupported older TLS protocol requests
(GH#1273)
- Fix memory disclosure to RADIUS servers by mod_radius (GH#1284)
- Properly handle sections that use interface/device names
(GH#1282)
- PCRE expressions with capture groups are not being handled properly
(GH#1300)
- AuthUserFile permissions check fails during SIGHUP, causing ProFTPD to
stop (GH#1307)
* Fri Jul 23 2021 Fedora Release Engineering - 1.3.7b-3
- Rebuilt for   https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Jun 22 2021 Paul Howarth - 1.3.7b-2
- BR: glibc-gconv-extra for API tests from Fedora 35 onwards
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2001690 - proftpd: memory disclosure to RADIUS servers by mod_radius
  https://bugzilla.redhat.com/show_bug.cgi?id=2001690
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-0a148b34a5' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys