Site Navigation:
security proftpd-1.3.3g-2.el6 security update
Status:stable
Release: Fedora EPEL 6
Update ID: FEDORA-EPEL-2013-0157
Builds: proftpd-1.3.3g-2.el6 (logs)
Pushed: True
Date Submitted: 2013-01-18 17:45:49
Date Released: 2013-01-22 02:44:07
Submitter: pghmcfc
Karma: 0
Details

Jann Horn reported that there is a possible race condition in the handling of the MKD/XMKD FTP commands, when the UserOwner directive is involved, and the attacker is on the same physical machine as a running proftpd. This race applies to mod_sftp and the handling of the MKDIR SFTP request as well.

Note that using the DefaultRoot directive to restrict sessions mitigates this attack, since the symlinks created by the local attacker will point outside of the chroot(2) area within the FTP session, and thus the ownership change will fail. The default configuration in EPEL applies the DefaultRoot directive to all users except "adm".

The upstream reference for this issue is: http://bugs.proftpd.org/show_bug.cgi?id=3841

This update includes a backport to 1.3.3g of upstream's backport to proftpd 1.3.4 of the fix for this issue.

Bugs Fixed
892715 - CVE-2012-6095: proftpd: Symlink race condition when applying UserOwner to a newly (ProFTPD) created directory
892719 - CVE-2012-6095: proftpd: Symlink race condition when applying UserOwner to a newly (ProFTPD) created directory [epel-all]
Feedback
bodhi - 2013-01-18 17:46:17
This update has been submitted for testing by pghmcfc.
bodhi - 2013-01-22 01:39:04
This update is currently being pushed to the Fedora EPEL 6 testing updates repository.
bodhi - 2013-01-22 03:39:55
This update has been pushed to testing
bodhi - 2013-02-05 10:05:41
This update has reached 14 days in testing and can be pushed to stable now if the maintainer wishes
bodhi - 2013-02-05 10:42:45
This update has been submitted for stable by pghmcfc.
bodhi - 2013-02-05 19:33:48
This update is currently being pushed to the Fedora EPEL 6 stable updates repository.
bodhi - 2013-02-05 21:25:30
This update has been pushed to stable

Add a comment

Tip: Login to impact how quickly this update gets pushed or unpushed.
obfuscated letters