| Summary: | pure-ftpd: Security issues fixed in 1.0.43 | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | alli <allison> |
| Component: | pure-ftpd | Assignee: | Ondřej Lysoněk <olysonek> |
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | epel7 | CC: | allison, gregswift, mi, olysonek |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | pure-ftpd-1.0.47-2.el7 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-03-12 21:07:47 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
alli
2016-11-23 16:48:45 UTC
To provide an update here, the version of pure-ftpd is now up to 1.0.47 and there are very serious changes that were made to the way that it handles cipher suites; also, one of the later versions disables TLSv1.0, which is useful for PCI compliance. It would be helpful to either backport the cipher suite fixes if maintaining TLSv1.0 backwards compatibility is important or update the package version on EPEL if it's not. pure-ftpd-1.0.47-1.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-675ebc0315 pure-ftpd-1.0.47-1.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-675ebc0315 pure-ftpd-1.0.47-2.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-675ebc0315 pure-ftpd-1.0.47-2.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-675ebc0315 pure-ftpd-1.0.47-2.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report. |