Oval Definition:oval:org.opensuse.security:def:74945
Revision Date:2020-12-01Version:1
Title:Security update for uftpd (Moderate)
Description:

This update for uftpd fixes the following issues:

uftpd was updated to version 2.12.

Changes:

Use common log message format and log level when user enters an invalid path. This unfortunately affects changes introduced in v2.11 to increase logging at default log level.

Security fixes:

- CVE-2020-14149: When entering an invalid directory with the FTP command CWD, a NULL ptr was deref. in a DBG() message even though the log level is set to a value lower than LOG_DEBUG. This caused uftpd to crash and cause denial of service. Depending on the init/inetd system used this could be permanent. (boo#1172959)
Family:unixClass:patch
Status:Reference(s):1172959
1175757
1176306
1176450
CVE-2020-14149
CVE-2020-15959
CVE-2020-6558
CVE-2020-6559
CVE-2020-6560
CVE-2020-6561
CVE-2020-6562
CVE-2020-6563
CVE-2020-6564
CVE-2020-6565
CVE-2020-6566
CVE-2020-6567
CVE-2020-6568
CVE-2020-6569
CVE-2020-6570
CVE-2020-6571
CVE-2020-6573
CVE-2020-6574
CVE-2020-6575
CVE-2020-6576
openSUSE-SU-2020:0865-1
openSUSE-SU-2020:1499-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND uftpd-2.12-lp151.2.6 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • chromedriver-85.0.4183.102-lp152.2.30 is installed
  • OR chromium-85.0.4183.102-lp152.2.30 is installed
  • BACK