Bug#500278: ftpd command line split

2008-09-28 Thread Ian Beckwith
tags 500278 + patch security clone 500278 -1 reassign -1 ftpd-ssl thanks Unfortunately this came in just as I was going on VAC. Whoever fixes this in linux-ftpd please NMU linux-ftpd-ssl as well. If nobody NMUs, I'll fix this in linux-ftpd-ssl after I get back from VAC. The attached patch is a po

Bug#500278: ftpd: command line split (CSRF)

2008-09-26 Thread Paul Szabo
Package: ftpd Version: 0.17-23 Severity: normal Similar to recent OpenBSD changes: http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpcmd.y this Debian package seems vulnerable to the same issue (and I expect the solution here to be the same). See also: multiple vendor ftpd - Cross-site r