-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2338-2 [email protected] https://www.debian.org/lts/security/ Markus Koschany August 25, 2020 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : proftpd-dfsg Version : 1.3.5e+r1.3.5b-4+deb9u2 Debian Bug : 968967 The update of proftpd-dfsg released as DLA-2338-1 incorrectly destroyed the memory pool in function sftp_kex_handle in contrib/mod_sftp/kex.c which may cause a segmentation fault and thus prevent sftp connections. For Debian 9 stretch, this problem has been fixed in version 1.3.5e+r1.3.5b-4+deb9u2. We recommend that you upgrade your proftpd-dfsg packages. For the detailed security status of proftpd-dfsg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/proftpd-dfsg Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl9FaglfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeT2IA/+IqH/t96aJ47stWhdI5dU4NCXESkYUkdPBdG2MHVSJuqOILj1ljtn6TFG 2NoxqRmrnHs71lqafJ5uhABcIIE9/xaEzYaDkhXnDuS8/NQAv3Qe1QP22sW2QjKk XDPVPYOB0K/y0weuGPEk8g+XF5s9p0uLLQLUTGRZBidYTGdN6oRlkdU2O1Ga8izf BHS5kHa+KviUSldCF2A9hUvQHWYLKwvySelzyPAHav6I4OulTldIiKc8UOXZ2G3x P7nRmZ3kHGkpfJNn5wjXDWNFXv+jONaISHZDXUcH4Mouxekcvz+xrlT5tEDKnPvS rT6mgarWBqGPrKVClFALnnQ2IvAuwH3AEScpq+Nu5zINlEOMOxoEXn7W3US8bnpK njwCSaAqfpWg36PV/9VVCy4OMxlepEd/CgcJbOfAU0AYhgkEBYIMiqFRCr3/jUbM /g+3pNhyKmBfhGwnHes0BK6hlAbNAAeG8GsQSS4A6yTItcOlhA9phnWbnj5+SePt +URUsh40rHj71yMGl6xbStrMt4KHDo9qWlP77+YcU8m+ehnJSaK01ohDmQleUvj1 Z07MDNGXwGuZCP9uJPbnW/Im4G5EDef8t9sVw00hS07QyNaXzxvY9VS25Yhys7V1 HuGV45qzZOcci6K28tiXbzBf7ucNVvqzQ/HXc70COH2KN/UBlCo= =U9q9 -----END PGP SIGNATURE-----
