Pure-FTPd has released version 1.0.30 which fixes a STARTTLS flaw similar to Postfix's CVE-2011-0411 [1]. Upgrading is recommended. References: [1] http://www.pureftpd.org/project/pure-ftpd/news
Created pure-ftpd tracking bugs for this issue Affects: fedora-all [bug 683223] Affects: epel-all [bug 683224]
This was assigned the name CVE-2011-1575: http://permalink.gmane.org/gmane.comp.security.oss.general/4858