segfault in xenial proftpd-dfsg 1.3.5a mod_sftp

Bug #1647094 reported by Jason Short
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
proftpd-dfsg (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

We have observed segfaults in mod_sftp that appear to be triggered by behavior in Ruby/Net::SSH as used by a software deployment service "deploybot.com".

Per https://github.com/proftpd/proftpd/issues/305, and based on our testing, the segfault is mitigated by this patch: https://github.com/proftpd/proftpd/commit/b5c407771e8aaa41811199e595116bfe0f36afb9

Our rebuilt proftpd-basic package has been running without segfaults during connections from this client.

Tags: patch
Revision history for this message
Jason Short (shortj) wrote :
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "https://github.com/proftpd/proftpd/commit/b5c407771e8aaa41811199e595116bfe0f36afb9" seems to be a patch. If it isn't, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are a member of the ~ubuntu-reviewers, unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by ~brian-murray, for any issues please contact him.]

tags: added: patch
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package proftpd-dfsg - 1.3.5d-1

---------------
proftpd-dfsg (1.3.5d-1) unstable; urgency=medium

  [ Hilmar Preuße ]
  * Init script (rarely) fails in detecting pid file (Closes: #756637)
  * Fix dep of proftpd-dev (libssl-dev -> libssl1.0-dev)
    (Closes: #848124)
  * Remove shlib-calls-exit from lintian overrides (warning is gone)
  * Reformat debian/*NEWS files (kills syntax-error-in-debian-news-file,
    removed lintian override).
  * Clean proftpd-basic.dirs a little bit. Kill proftpd-dev.dirs.
  * Tighten B-D version of debhelper (dh_update_autotools_config was
    introduced).
  * Patch github_305_handling_unclosed_files
    When handling unclosed files for an aborted SFTP session, we will
    need a valid response pool. So provide one. The lack of this may have
    been causing some segfaults. (LP: #1647094)
  * Patch bug_4277_deb_823409
    Upstream identified another Memleak, occurring when /uploading/ large
    files; affects only 1.3.5 line. Patch hopefully (Closes: #823409).

  [ Francesco Paolo Lovergine ]
  * New upstream release. (Closes: #854369)
    * Patchset updated to remove already included patches.
    * Build w/ OpenSSL 1.1. Do it (Closes: #828513)
  * Makes piuparts happy by removing /srv/ftp on purge
  * Removed debconf support and added a proftpd-basic.NEWS entry to warn about
    that. (Closes: #820984)

 -- Francesco Paolo Lovergine <email address hidden> Thu, 26 Jan 2017 13:23:53 +0100

Changed in proftpd-dfsg (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.