Updated proftpd packages fix security vulnerability
Publication date: 26 Feb 2025Modification date: 26 Feb 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-57392
Description
A buffer overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a denial of service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port. (CVE-2024-57392)
References
- https://bugs.mageia.org/show_bug.cgi?id=34042
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E36XSNXDCOSSYTPKEMAEUAZ6QVQJTSFZ/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/C3HZA5IS6YXHXDULEZHLHWOVCC3IYNGP/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57392
SRPMS
9/core
- proftpd-1.3.8c-1.1.mga9