Your message dated Fri, 01 Oct 2021 19:32:21 +0000
with message-id <[email protected]>
and subject line Bug#991394: fixed in proftpd-dfsg 1.3.6-4+deb10u6
has caused the Debian Bug report #991394,
regarding proftpd-basic: mod_sftp is missing an upstream fix: #866 "mod_sftp
crashes when using pubkey-auth with DSA keys"
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
991394: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991394
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: proftpd-basic
Version: 1.3.6-4+deb10u5
Severity: normal
Dear Maintainer,
When connecting to proftpd daemon using SFTP protocol and authenticating
using a DSS key, the server process crashes with segmentation fault.
This is caused by an upstream issue #866
(https://github.com/proftpd/proftpd/issues/866) that is fixed in PR #867
(https://github.com/proftpd/proftpd/pull/867).
The issue happens in module mod_sftp that has an obvious copy-paste
error in the code. The upstream fix #867 reliably solves the issue.
With Best Regards,
Igor
--- End Message ---
--- Begin Message ---
Source: proftpd-dfsg
Source-Version: 1.3.6-4+deb10u6
Done: Hilmar Preusse <[email protected]>
We believe that the bug you reported is fixed in the latest version of
proftpd-dfsg, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Hilmar Preusse <[email protected]> (supplier of updated proftpd-dfsg package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 18 Sep 2021 23:05:52 +0200
Source: proftpd-dfsg
Architecture: source
Version: 1.3.6-4+deb10u6
Distribution: buster
Urgency: medium
Maintainer: ProFTPD Maintainance Team
<[email protected]>
Changed-By: Hilmar Preusse <[email protected]>
Closes: 971742 991394 993173
Changes:
proftpd-dfsg (1.3.6-4+deb10u6) buster; urgency=medium
.
* Add patch for Issue #1119: Cannot disable client-initiated
renegotiation for FTPS
https://github.com/proftpd/proftpd/issues/1119
* Bug #4332: Fix navigation into symlinked directories by
removing interfering code added as part of Bug#4219.
(Closes: #971742)
* Add patch for issue #866: (Closes: #991394)
mod_sftp crashes when using pubkey-auth with DSA keys
* Add patch for upstream issue #1284 (Closes: #993173).
* Add me to Uploaders.
Checksums-Sha1:
caea7e3f1cfb0ce4ae4b7908c92f0107490d582a 3002 proftpd-dfsg_1.3.6-4+deb10u6.dsc
5f97dae86ef1807a614abc1fb86088991a085ead 83812
proftpd-dfsg_1.3.6-4+deb10u6.debian.tar.xz
e3fafce14333efd04d71356e6433d5164142e4be 7306
proftpd-dfsg_1.3.6-4+deb10u6_source.buildinfo
Checksums-Sha256:
18d8863c022d17e828128030ff6c896a4f9615639d45f8871669b7e9dcd48a92 3002
proftpd-dfsg_1.3.6-4+deb10u6.dsc
faee5017e2a485e5c63674d3ceac0a35485e94c389383aa2556fa891a5b53020 83812
proftpd-dfsg_1.3.6-4+deb10u6.debian.tar.xz
05f52a74d34efa9d65339ce258d20601304dd64fd2dbfe2e1004304e1d05b71d 7306
proftpd-dfsg_1.3.6-4+deb10u6_source.buildinfo
Files:
c901897de46fe11ac3c84f37a623845b 3002 net optional
proftpd-dfsg_1.3.6-4+deb10u6.dsc
d44aac02708a6e8d2226dc14f5d2622c 83812 net optional
proftpd-dfsg_1.3.6-4+deb10u6.debian.tar.xz
e080c1b6e0ab17c885908e48c2eb1a9b 7306 net optional
proftpd-dfsg_1.3.6-4+deb10u6_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEEaXGmC/nkbIhxf16kxiZYRqvgLIsFAmFGVc9fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDY5
NzFBNjBCRjlFNDZDODg3MTdGNUVBNEM2MjY1ODQ2QUJFMDJDOEIACgkQxiZYRqvg
LIvO3xAAgPelv64mAipm8ZvDSCc4Rr6YrlUDQThwvHCWYTUhFYTHvtwAurllzyf1
drTK1Tt2uDs0D7CBvWM703+cHzQZoxHP1yu/f7VkvWXjjpO7UElJzzjavOslHLRu
OVzaeBp3lWVQJEi0ONxuMUVcuBd7Nj7Sqn/cqkyeYHh1gcuDZ6nI9YVcWS3ipVOC
1MGdQKjQRRLYNEm/ydLsVzV7jn8S24l+RbDzVG67deCqiLxHzQEAVO+z4JXqQDfr
LHws5VYJ36b5PBImnH+Lw/lVX1B1EOxuGZ1xRE8VHGMZyVCTA8pMH7DsOUNh1nD6
KKt3VC0Ank71rU9TBy4vcNoDNHTKMGoFrC84oo6PIczprRhKgST+n5n0AE5VOZtt
5LOQewrEdr7VyglPsjShQit1G0VS0PJgIqCTpQEy6MybaWtYBuebCG8xudbfVLfp
IDOvXIJmPB/dBNJM57Dl25ez7yVgD7NNDuSAT1FZPNHyTQT7jheg6toE4b1DRFBm
MJM5MjtkOoKTnMmLlTT6lLi+x1OfMPXmRbpFjbwPud4UsvRLtNQoU6Zt/71/v63+
MlY8lDvqx5jqUagN0MRZyeo0ZstuqitwjBjivh4QFD7HtqkixvTpIjWTNuKqlvn1
BnNzBIipnEIf9LBg+f1Y4ECpiiYbPmEQDwwVA8AojBYGj7NqawY=
=CC+E
-----END PGP SIGNATURE-----
--- End Message ---