Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 347598 - net-ftp/proftpd source code compromised
Summary: net-ftp/proftpd source code compromised
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-12-02 20:27 UTC by Mark Wagner
Modified: 2010-12-02 21:15 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mark Wagner 2010-12-02 20:27:28 UTC
As announced at http://www.proftpd.org/, between November 28 and December 2, the source code for ProFTPD 1.3.3c on the ProFTPD site and all mirrors was compromised.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-12-02 20:57:11 UTC
The proftpd ebuild was bumped to 1.3.3c on November 03, and the Manifest was generated at the same time.

I have confirmed that our Manifest matches the "good" version.
Also, I looked at a random sample (20) of our mirrors, none offer the compromised version.

Gentoo thus is not affected.