Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1727-1] New proftpd-dfsg packages fix SQL injection vul

    From Steffen Joeris@1:229/2 to All on Thu Feb 26 09:50:07 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - -------------------------------------------------------------------------- Debian Security Advisory DSA 1727-1 [email protected] http://www.debian.org/security/ Steffen Joeris February 26th, 2009 http://www.debian.org/security/faq
    - --------------------------------------------------------------------------

    Package : proftpd-dfsg
    Vulnerability : SQL injection vulnerabilites
    Problem type : remote
    Debian-specific: no
    CVE Ids : CVE-2009-0542 CVE-2009-0543

    Two SQL injection vulnerabilities have been found in proftpd, a
    virtual-hosting FTP daemon. The Common Vulnerabilities and Exposures
    project identifies the following problems:

    CVE-2009-0542

    Shino discovered that proftpd is prone to an SQL injection
    vulnerability via the use of certain characters in the username.

    CVE-2009-0543

    TJ Saunders discovered that proftpd is prone to an SQL injection
    vulnerability due to insufficient escaping mechanisms, when
    multybite character encodings are used.

    For the stable distribution (lenny), these problems have been fixed in
    version 1.3.1-17lenny1.

    For the oldstable distribution (etch), these problems will be fixed
    soon.

    For the testing distribution (squeeze), these problems will be fixed
    soon.

    For the unstable distribution (sid), these problems have been fixed in
    version 1.3.2-1.

    We recommend that you upgrade your proftpd-dfsg package.


    Upgrade Instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given at the end of this advisory:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.1-17lenny1.dsc
    Size/MD5 checksum: 1348 bb4118976a78b6eef4356123b4e322da
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.1-17lenny1.diff.gz
    Size/MD5 checksum: 102388 7873fdab33c5e044dce721300d496d7e
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-dfsg_1.3.1.orig.tar.gz
    Size/MD5 checksum: 2662056 da40b14c5b8ec5467505c98b4ee4b7b9

    Architecture independent components:

    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-doc_1.3.1-17lenny1_all.deb
    Size/MD5 checksum: 1256300 f0e73bd54793839c802b3c3ce85bb123
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd_1.3.1-17lenny1_all.deb
    Size/MD5 checksum: 194896 cda6edb78e4a5ab9c8a90cfdaeb19b32

    AMD64 architecture:

    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-basic_1.3.1-17lenny1_amd64.deb
    Size/MD5 checksum: 744914 4c09f5af5f825f0c068f3dce4a1c7a84
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-ldap_1.3.1-17lenny1_amd64.deb
    Size/MD5 checksum: 214334 eb8f6f56afda836f85f6d808a6086c6a
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-mysql_1.3.1-17lenny1_amd64.deb
    Size/MD5 checksum: 203878 8d13ce2c0d2c15eec496d3e014aa1ea3
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-pgsql_1.3.1-17lenny1_amd64.deb
    Size/MD5 checksum: 203902 ce74fcf7e0f082fcf4454120e984a0c3

    ARM architecture:

    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-basic_1.3.1-17lenny1_arm.deb
    Size/MD5 checksum: 696884 cab353aa755852b2c07916f234268e39
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-ldap_1.3.1-17lenny1_arm.deb
    Size/MD5 checksum: 213832 faad0df7dab14fdca108c6370ae3edf0
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-mysql_1.3.1-17lenny1_arm.deb
    Size/MD5 checksum: 203260 3940f22df22db3ce6a3644a22b68e82b
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-pgsql_1.3.1-17lenny1_arm.deb
    Size/MD5 checksum: 203448 35f6cb99d5f9886d74a8a1e72df36a2d

    Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-basic_1.3.1-17lenny1_i386.deb
    Size/MD5 checksum: 688540 bdcbe2b33ed58bf474824c4639dcfb99
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-ldap_1.3.1-17lenny1_i386.deb
    Size/MD5 checksum: 212208 bcb4bce6c950fe4fd416fcf9e97b79f6
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-mysql_1.3.1-17lenny1_i386.deb
    Size/MD5 checksum: 203074 55e8334da716aeb8efe43803c8f71d00
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-pgsql_1.3.1-17lenny1_i386.deb
    Size/MD5 checksum: 203054 189e02b962d043af8bbb0b29ac61e881

    Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-basic_1.3.1-17lenny1_ia64.deb
    Size/MD5 checksum: 980498 6129efd03c600138d89d341dfd2b9641
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-ldap_1.3.1-17lenny1_ia64.deb
    Size/MD5 checksum: 221974 3aea4ff6d0dd4729a901a21ddfefe18c
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-mysql_1.3.1-17lenny1_ia64.deb
    Size/MD5 checksum: 207238 2670aca7f909b86c6b567e2a1ac44917
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-pgsql_1.3.1-17lenny1_ia64.deb
    Size/MD5 checksum: 207126 9f52b57603c3d47c354edb2c460e0aa1

    Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-basic_1.3.1-17lenny1_mips.deb
    Size/MD5 checksum: 691342 6d88d7863198638c168ac1de05d5cb49
    http://security.debian.org/pool/updates/main/p/proftpd-dfsg/proftpd-mod-ldap_1.3.1-17lenny1_mips.deb
    Size/MD5 checksum: 212038 d1e82db5072e2f62f5f84e2daf86f978

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
    • Michal Wronka
      Thu Jun 4 23:19:58 2026
      from Wroclaw, Poland via Telnet
    • Michal Wronka
      Thu Jun 4 23:17:20 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 144:13:31
    Calls: 12,089
    Calls today: 2
    Files: 15,000
    Messages: 6,517,483

© >>> Magnum BBS <<<, 2026