Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 538130 (CVE-2015-1419) - <net-ftp/vsftpd-3.0.3-r2: access restrictions bypass (CVE-2015-1419)
Summary: <net-ftp/vsftpd-3.0.3-r2: access restrictions bypass (CVE-2015-1419)
Status: RESOLVED FIXED
Alias: CVE-2015-1419
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on: 659326
Blocks:
  Show dependency tree
 
Reported: 2015-01-29 10:51 UTC by Agostino Sarubbo
Modified: 2019-03-24 01:45 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-01-29 10:51:30 UTC
From ${URL} :

Common Vulnerabilities and Exposures assigned an identifier CVE-2015-1419 to the following vulnerability:

Name: CVE-2015-1419
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1419
Assigned: 20150127
Reference: http://secunia.com/advisories/62415

Unspecified vulnerability in vsftp 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2015-02-11 18:24:25 UTC
CVE-2015-1419 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1419):
  Unspecified vulnerability in vsftp 3.0.2 and earlier allows remote attackers
  to bypass access restrictions via unknown vectors, related to deny_file
  parsing.
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2016-11-19 15:39:13 UTC
While Red Hat not consider this issue as a security flaw because man page document the behavior, SuSE and Debian are carrying https://anonscm.debian.org/cgit/collab-maint/vsftpd.git/tree/debian/patches/0050-CVE-2015-1419.patch


@ Maintainer(s): Please tell us how you want to proceed here. Are you going to rev-bump and include the patch as well?