{"id":"openSUSE-SU-2020:0031-1","summary":"Security update for proftpd","details":"This update for proftpd fixes the following issues:\n\n* GeoIP has been discontinued by Maxmind (boo#1156210)\n  This update removes module build for geoip\n    see https://support.maxmind.com/geolite-legacy-discontinuation-notice/\n\n- CVE-2019-19269: Fixed a NULL pointer dereference may occur when validating the certificate of a client connecting to the server (boo#1157803)\n- CVE-2019-19270: Fixed a Failure to check for the appropriate field of a CRL entry prevents some valid CRLs from being taken into account (boo#1157798)\n- CVE-2019-18217: Fixed remote unauthenticated denial-of-service due to incorrect handling of overly long commands (boo#1154600 gh#846)\n\nUpdate to 1.3.6b\n\n* Fixed pre-authentication remote denial-of-service issue (Issue #846).\n* Backported fix for building mod_sql_mysql using MySQL 8 (Issue #824).\n\nUpdate to 1.3.6a:\n\n* Fixed symlink navigation (Bug#4332).\n* Fixed building of mod_sftp using OpenSSL 1.1.x releases (Issue#674).\n* Fixed SITE COPY honoring of \u003cLimit\u003e restrictions (Bug#4372).\n* Fixed segfault on login when using mod_sftp + mod_sftp_pam (Issue#656).\n* Fixed restarts when using mod_facl as a static module\n* Add missing Requires(pre): group(ftp) for Leap 15 and Tumbleweed (boo#1155834)\n* Add missing Requires(pre): user(ftp) for Leap 15 and Tumbleweed (boo#1155834)\n* Use pam_keyinit.so (boo#1144056)\n\n- Reduce hard dependency on systemd to only that which is\n  necessary for building and installation.\n\nupdate to 1.3.6:\n\n* Support for using Redis for caching, logging; see the doc/howto/Redis.html\n  documentation.\n* Fixed mod_sql_postgres SSL support (Issue #415).\n* Support building against LibreSSL instead of OpenSSL (Issue #361).\n* Better support on AIX for login restraictions (Bug #4285).\n* TimeoutLogin (and other timeouts) were not working properly for SFTP\n  connections (Bug#4299).\n* Handling of the SIGILL and SIGINT signals, by the daemon process, now causes\n  the child processes to be terminated as well (Issue #461).\n* RPM .spec file naming changed to conform to Fedora guidelines.\n* Fix for 'AllowChrootSymlinks off' checking each component for symlinks (CVE-2017-7418).\n\nNew Modules:\n\n* mod_redis, mod_tls_redis, mod_wrap2_redis\n    With Redis now supported as a caching mechanism, similar to Memcache,\n    there are now Redis-using modules: mod_redis (for configuring the Redis\n    connection information), mod_tls_redis (for caching SSL sessions and\n    OCSP information using Redis), and mod_wrap2_redis (for using ACLs stored\n    in Redis).\n\nChanged Modules:\n\n* mod_ban:\n      The mod_ban module's BanCache directive can now use Redis-based caching;\n      see doc/contrib/mod_ban.html#BanCache.\n\n-New Configuration Directives\n\n* SQLPasswordArgon2, SQLPasswordScrypt\n\n      The key lengths for Argon2 and Scrypt-based passwords are now configurable\n      via these new directives; previously, the key length had been hardcoded\n      to be 32 bytes, which is not interoperable with all other implementations\n      (Issue #454).\n\nChanged Configuration Directives\n\n* AllowChrootSymlinks\n    When 'AllowChrootSymlinks off' was used, only the last portion of the\n    DefaultRoot path would be checked to see if it was a symlink.  Now,\n    each component of the DefaultRoot path will be checked to see if it is\n    a symlink when 'AllowChrootSymlinks off' is used.\n* Include\n    The Include directive can now be used within a \u003cLimit\u003e section, e.g.:\n      \u003cLimit LOGIN\u003e\n          Include /path/to/allowed.txt\n          DenyAll\n        \u003c/Limit\u003e\nAPI Changes\n  * A new JSON API has been added, for use by third-party modules. \n\n","modified":"2026-03-11T07:32:21.273638Z","published":"2020-01-13T15:20:23Z","related":["CVE-2017-7418","CVE-2019-12815","CVE-2019-18217","CVE-2019-19269","CVE-2019-19270"],"upstream":["CVE-2017-7418","CVE-2019-12815","CVE-2019-18217","CVE-2019-19269","CVE-2019-19270"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YQAELVZ2VM7ZCMMAPQ4KYBJ6KWLXIVC2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1113041"},{"type":"REPORT","url":"https://bugzilla.suse.com/1144056"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154600"},{"type":"REPORT","url":"https://bugzilla.suse.com/1155834"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156210"},{"type":"REPORT","url":"https://bugzilla.suse.com/1157798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1157803"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7418"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19269"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19270"}],"affected":[{"package":{"name":"proftpd","ecosystem":"SUSE:Package Hub 15","purl":"pkg:rpm/suse/proftpd&distro=SUSE%20Package%20Hub%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.6b-bp151.4.6.2"}]}],"ecosystem_specific":{"binaries":[{"proftpd-pgsql":"1.3.6b-bp151.4.6.2","proftpd-radius":"1.3.6b-bp151.4.6.2","proftpd-sqlite":"1.3.6b-bp151.4.6.2","proftpd":"1.3.6b-bp151.4.6.2","proftpd-devel":"1.3.6b-bp151.4.6.2","proftpd-doc":"1.3.6b-bp151.4.6.2","proftpd-ldap":"1.3.6b-bp151.4.6.2","proftpd-lang":"1.3.6b-bp151.4.6.2","proftpd-mysql":"1.3.6b-bp151.4.6.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0031-1.json"}},{"package":{"name":"proftpd","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/proftpd&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.6b-bp151.4.6.2"}]}],"ecosystem_specific":{"binaries":[{"proftpd-mysql":"1.3.6b-bp151.4.6.2","proftpd-radius":"1.3.6b-bp151.4.6.2","proftpd":"1.3.6b-bp151.4.6.2","proftpd-devel":"1.3.6b-bp151.4.6.2","proftpd-lang":"1.3.6b-bp151.4.6.2","proftpd-ldap":"1.3.6b-bp151.4.6.2","proftpd-pgsql":"1.3.6b-bp151.4.6.2","proftpd-sqlite":"1.3.6b-bp151.4.6.2","proftpd-doc":"1.3.6b-bp151.4.6.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0031-1.json"}},{"package":{"name":"proftpd","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/proftpd&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.6b-bp151.4.6.2"}]}],"ecosystem_specific":{"binaries":[{"proftpd-lang":"1.3.6b-bp151.4.6.2","proftpd-ldap":"1.3.6b-bp151.4.6.2","proftpd-mysql":"1.3.6b-bp151.4.6.2","proftpd-radius":"1.3.6b-bp151.4.6.2","proftpd-devel":"1.3.6b-bp151.4.6.2","proftpd-doc":"1.3.6b-bp151.4.6.2","proftpd-pgsql":"1.3.6b-bp151.4.6.2","proftpd-sqlite":"1.3.6b-bp151.4.6.2","proftpd":"1.3.6b-bp151.4.6.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0031-1.json"}}],"schema_version":"1.7.5"}