Bug#992920: Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-27 Thread Hilmar Preuße
Am 19.09.2021 um 00:13 teilte Adam D. Barratt mit: Hi Adam, Thanks, and apologies if I was slightly impatient in jumping on the uploads. In general, however, we'd expect the unstable upload to at least have happened first, if not to have also had some time to weed out any obvious issues.

Bug#993173: Bug#992920: Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-18 Thread Adam D. Barratt
On Sun, 2021-09-19 at 00:08 +0200, Hilmar Preuße wrote: > Am 19.09.2021 um 00:03 teilte Adam D. Barratt mit: > > Hi, > > > However, neither appears to be fixed in unstable yet. Is that > > correct? > > If so, please resolve the issues in unstable first, as that is a > > basic > > prerequisite

Bug#992920: Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-18 Thread Hilmar Preuße
Am 19.09.2021 um 00:03 teilte Adam D. Barratt mit: Hi, However, neither appears to be fixed in unstable yet. Is that correct? If so, please resolve the issues in unstable first, as that is a basic prerequisite for fixing them in (old)stable. If the issues are in fact fixed in unstable, please

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-18 Thread Adam D. Barratt
Hi, On Sat, 2021-09-18 at 18:41 +0200, Hilmar Preuße wrote: > Am 18.09.2021 um 12:01 teilte Salvatore Bonaccorso mit: > > On Sat, Sep 18, 2021 at 11:09:18AM +0200, Chris Hofstaedtler wrote: > > > * Chris Hofstaedtler [210904 13:27]: > > > > * Hilmar Preuße [210903 10:42]: > > Hi, > > > > > >

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-18 Thread Hilmar Preuße
Am 18.09.2021 um 12:01 teilte Salvatore Bonaccorso mit: On Sat, Sep 18, 2021 at 11:09:18AM +0200, Chris Hofstaedtler wrote: * Chris Hofstaedtler [210904 13:27]: * Hilmar Preuße [210903 10:42]: Hi, Try here: https://freeshell.de/hille42/993173/ I have tried these packages out (on

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-18 Thread Salvatore Bonaccorso
Hi, On Sat, Sep 18, 2021 at 11:09:18AM +0200, Chris Hofstaedtler wrote: > Hello Hilmar, > > * Chris Hofstaedtler [210904 13:27]: > > * Hilmar Preuße [210903 10:42]: > > > Try here: https://freeshell.de/hille42/993173/ > > > > I have tried these packages out (on buster, obviously), and can > >

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-18 Thread Chris Hofstaedtler
Hello Hilmar, * Chris Hofstaedtler [210904 13:27]: > * Hilmar Preuße [210903 10:42]: > > Try here: https://freeshell.de/hille42/993173/ > > I have tried these packages out (on buster, obviously), and can > confirm they work as expected. Also together with proftpd-mod-vroot. Do you think this

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-04 Thread Chris Hofstaedtler
Hi, * Hilmar Preuße [210903 10:42]: > Am 02.09.2021 um 10:11 teilte Chris Hofstaedtler mit: > > * Hilmar Preuße [210901 08:28]: > > > - Are you willing to test the fix before I upload? > > > > I can easily test on oldstable (=buster), but not on bullseye. > > > Try here:

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-03 Thread Hilmar Preuße
Control: found -1 1.3.7b+dfsg-2 OpenPGP_signature Description: OpenPGP digital signature

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-03 Thread Hilmar Preuße
Control: found -1 1.3.7b-2 Am 02.09.2021 um 10:11 teilte Chris Hofstaedtler mit: * Hilmar Preuße [210901 08:28]: Hi, I've pushed the patch to stable and oldstable branch. Further I've packaged the 1.3.7c for unstable and would upload soon. Thanks a lot! - Do we need to have the fix in

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-02 Thread Chris Hofstaedtler
Hello, * Hilmar Preuße [210901 08:28]: > Am 28.08.2021 um 13:31 teilte Chris Hofstaedtler mit: > > it has been found that proftpd's mod_radius leaks uninitialised memory > > to the RADIUS server, as part of the encrypted User-Password. > > > > Upstream report:

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-09-01 Thread Hilmar Preuße
X-Debbugs-Cc: Debian Security Team Am 28.08.2021 um 13:31 teilte Chris Hofstaedtler mit: Hi all, it has been found that proftpd's mod_radius leaks uninitialised memory to the RADIUS server, as part of the encrypted User-Password. Upstream report:

Bug#993173: proftpd-basic: mod_radius leaks memory contents to radius server

2021-08-28 Thread Chris Hofstaedtler
Package: proftpd-basic Version: 1.3.6-4+deb10u5 Severity: normal Tags: security X-Debbugs-Cc: Debian Security Team Hi, it has been found that proftpd's mod_radius leaks uninitialised memory to the RADIUS server, as part of the encrypted User-Password. Upstream report: