On 2/29/20 8:58 AM, Nikolai Lusan wrote:

Hi Nikolai,

> Sorry I haven't gotten back to you yet. I have a number of projects
> on the go, and since this is only impacting a small number of users
> on my home system it has fallen lower on my priority list - I was
> also trying to find solutions myself.
>
The reason why I ask is that we have a security issue in the proftp
1.3.6b in Debian testing, which has been solved in unstable. Therefore
I'd like to migrate that version ASAP. However I need to know if that
causes other issues, like incompatibility w/ mod-vroot, which needs to
be addressed by upstream.

> Apparently there are people that have the code from the upstream git 
> repository working with current proftpd, but I haven't had time to 
> dig into the differences in compilation methods.
> 
I've provided two possible solutions (downgrade proftpd and upgrade to
proftp-mod-vroot compiled w/ proftp v1.3.6c). Please try both and report
back if one of both solves the issue. Unfortunately I'm not very
familiar w/ the vroot module, hence I can't really help here. Please
call back ASAP.

Many thanks!

Hilmar
-- 
sigfault
#206401 http://counter.li.org



Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to