ELSA-2008-0680

ELSA-2008-0680 - vsftpd security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2008-08-01

Description


[2.0.1-6]
- add option max_login_fails that kicks the session after few login fails
- Resolves: #197141
- fix bad handling of unique files
- Resolves: #250727
- increase maximum length of allowed username
- Resolves: #236326
- fix create/lock race condition when more clients are uploading to a file
- Resolves: #240550
- document lock_upload_files option
- Resolves: #316381
- allow usernames to begin with underscore or dot
- Resolves: #339911
- dont reply with code 150 two times when uploading files with STOU
- Resolves: #387021
- fix memory leak in ls.c
- Resolves: #408431
- daemonize correctly and report startup failure correctly
- Resolves: #206843
- fix init script
- Resolves: #431450


Related CVEs


CVE-2008-2375

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 4 (i386) vsftpd-2.0.1-6.el4.src.rpm21a24742036ad65f3b2f1e20b319d742ELSA-2011-0337
vsftpd-2.0.1-6.el4.i386.rpmeb5d4815462ed201574b2fe58d4e8aaaELSA-2011-0337
Oracle Linux 4 (ia64) vsftpd-2.0.1-6.el4.src.rpm21a24742036ad65f3b2f1e20b319d742ELSA-2011-0337
vsftpd-2.0.1-6.el4.ia64.rpm1ab13dafc374eef2d72445be51d7e752ELSA-2011-0337
Oracle Linux 4 (x86_64) vsftpd-2.0.1-6.el4.src.rpm21a24742036ad65f3b2f1e20b319d742ELSA-2011-0337
vsftpd-2.0.1-6.el4.x86_64.rpm777fbffa3ce03c64bdec08b7cbd0db26ELSA-2011-0337



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete