Home / mailings [SECURITY] [DSA 1925-1] New proftpd-dfsg packages fix SSL certificate verification weakness
Posted on 01 November 2009
Debian Security Advisory-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- ------------------------------------------------------------------------
Debian Security Advisory DSA-1925-1 security@debian.org
http://www.debian.org/security/ Steffen Joeris
October 31, 2009 http://www.debian.org/security/faq
- ------------------------------------------------------------------------
Package : proftpd-dfsg
Vulnerability : insufficient input validation
Problem type : remote
Debian-specific: no
CVE Id : CVE-2009-3639
It has been discovered that proftpd-dfsg, a virtual-hosting FTP daemon,
does not properly handle a '