[Bug 401803] [NEW] gadmin-proftpd + ftps fails with Ubuntu 9.04

PJO paul at onolan.net
Mon Jul 20 15:59:12 UTC 2009


*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: gadmin-proftpd

See http://ubuntuforums.org/showthread.php?p=7646587#post7646587

It seems that gadmin-proftpd should have a button to generate
certificates (reportedly it does under Fedora, and it works -- see
ubuntuforums link above).

I generated the certificate and key manually using openssl and edited
the configuration to use them. The changes had no effect.

In so far as usernames and passwords continue to be transmitted in clear
text, given this failing, this is a security vulnerability.

The version of gadmin-proftpd installed was 1:0.3.5-2 [universe]
The version of proftpd installed was 1.3.1-17ubuntu1

** Affects: gadmin-proftpd (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

-- 
gadmin-proftpd + ftps fails with Ubuntu 9.04
https://bugs.launchpad.net/bugs/401803
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs at lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs




More information about the universe-bugs mailing list