Re: Proftpd and bug #319849

2005-08-12 Thread Christophe Chisogne
Vincent Bernat a écrit : > proftpd in Sarge is vulnerable to a format string vulnerability. The > corresponding bug is marked as fixed in 1.2.10-20 and found in > 1.2.10-15 (which is the Sarge version). This means that the Sarge > version is still vulnerable. Indeed, sarge proftpd

Proftpd and bug #319849

2005-08-11 Thread Vincent Bernat
Hi ! proftpd in Sarge is vulnerable to a format string vulnerability. The corresponding bug is marked as fixed in 1.2.10-20 and found in 1.2.10-15 (which is the Sarge version). This means that the Sarge version is still vulnerable. However, the bug is closed and not tagged security.