[Buildroot] [PATCH] package/proftpd: security bump to version 1.3.6c

Thomas Petazzoni thomas.petazzoni at bootlin.com
Thu Feb 27 17:26:36 UTC 2020


On Thu, 27 Feb 2020 14:54:56 +0100
Peter Korsgaard <peter at korsgaard.com> wrote:

> Fixes the following security issues:
> 
> - CVE-2020-9273: In ProFTPD 1.3.7, it is possible to corrupt the memory pool
>   by interrupting the data transfer channel.  This triggers a use-after-free
>   in alloc_pool in pool.c, and possible remote code execution.
> 
> And additionally, fixes a number of other issues.  For details, see the
> release notes:
> 
> https://github.com/proftpd/proftpd/blob/1.3.6/RELEASE_NOTES
> 
> This also bumps the bundled libcap, so
> 0001-fix-kernel-header-capability-version.patch can be dropped.
> 
> While we are at it, adjust the white space in the .hash function to match
> the new agreements.
> 
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
> ---
>  .../0001-fix-kernel-header-capability-version.patch  | 12 ------------
>  package/proftpd/proftpd.hash                         |  4 ++--
>  package/proftpd/proftpd.mk                           |  2 +-
>  3 files changed, 3 insertions(+), 15 deletions(-)
>  delete mode 100644 package/proftpd/0001-fix-kernel-header-capability-version.patch

Applied to master, thanks.

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


More information about the buildroot mailing list