MGASA-2015-0485

Source
https://advisories.mageia.org/MGASA-2015-0485.html
Import Source
https://advisories.mageia.org/MGASA-2015-0485.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0485
Published
2015-12-24T11:08:20Z
Modified
2026-04-16T04:27:56Z
Summary
Updated proftpd packages fix security vulnerabilities
Details

Updated proftpd packages fix security vulnerability:

Part of the SFTP handshake involves "extensions", which are key/value pairs, comprised of strings. In SSH, strings are encoded for network transport as a 32-bit length, followed by the bytes. The mod_sftp module currently places no bounds/length limitations when reading these SFTP extension key/value data from the network. A malicious attacker might attempt to encode large values, and allocate more memory than is necessary, causing excessive resource usage or the FTP daemon to crash (proftpd#4210).

This update also includes a fix for a crash in mod_lang (proftpd#4206).

References
Credits

Affected packages

Mageia:5 / proftpd

Package

Name
proftpd
Purl
pkg:rpm/mageia/proftpd?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.5-5.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0485.json"