Bug#496686: proftpd: SSL/TLS Module doesnt handel the rfc correct - connections can be spoofed

2008-09-13 Thread Thomas Creutz
Francesco P. Lovergine schrieb: Well, the security concerning are about clients (e.g. filezilla), which anyway should manage the issue in any case, AFAIK because people could not expect all servers are compliant. This is fixed in 1.3.1. No fix for the stable etch release? This is not

Bug#496686: proftpd: SSL/TLS Module doesnt handel the rfc correct - connections can be spoofed

2008-09-13 Thread Francesco P. Lovergine
On Sat, Sep 13, 2008 at 08:52:02AM +0200, Thomas Creutz wrote: Francesco P. Lovergine schrieb: Well, the security concerning are about clients (e.g. filezilla), which anyway should manage the issue in any case, AFAIK because people could not expect all servers are compliant. This is

Bug#496686: proftpd: SSL/TLS Module doesnt handel the rfc correct - connections can be spoofed

2008-08-27 Thread Francesco P. Lovergine
notfound 496686 1.3.1-1 thanks On Tue, Aug 26, 2008 at 08:27:03PM +0200, Thomas Creutz wrote: Package: proftpd Version: 1.3.0-19etch1 Severity: normal ProFTP TLS/SSL Module does not handle the RFC 4346 correct! So the connection can be vulnerable to spoofed FIN packets. See the follow

Bug#496686: proftpd: SSL/TLS Module doesnt handel the rfc correct - connections can be spoofed

2008-08-26 Thread Thomas Creutz
Package: proftpd Version: 1.3.0-19etch1 Severity: normal ProFTP TLS/SSL Module does not handle the RFC 4346 correct! So the connection can be vulnerable to spoofed FIN packets. See the follow addresses http://forum.filezilla-project.org/viewtopic.php?f=2t=7688 the bug report and a fix is