DSA-1925-1

NameDSA-1925-1
SourceDebian
Descriptionproftpd-dfsg - SSL certificate verification weakness
ReferencesCVE-2009-3639
Debian/oldstablepackage proftpd-dfsg is fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
proftpd-dfsg (PTS)etch1.3.0-19etch2vulnerable
etch (security)1.3.0-19etch3fixed
lenny, lenny (security)1.3.1-17lenny4fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
proftpdetch1.3.0-19etch2vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)1.3.0-19etch2vulnerablepowerpc
etch (security)1.3.0-19etch3fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, s390, sparc
proftpd, proftpd-doclenny, lenny (security)1.3.1-17lenny4fixedall
proftpd-basic, proftpd-mod-ldap, proftpd-mod-mysql, proftpd-mod-pgsqllenny, lenny (security)1.3.1-17lenny4fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
proftpd-doc, proftpd-ldap, proftpd-mysql, proftpd-pgsqletch1.3.0-19etch2vulnerableall
etch (security)1.3.0-19etch3fixedall

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
proftpd-dfsgsourceetch1.3.0-19etch3unknown
proftpd-dfsgsourcelenny1.3.1-17lenny4unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint