REDHAT-BUG-1493114: Medium severity Fedora pure-ftpd vulnerability
When rebasing pure-ftpd in Fedora 26, 27 and Rawhide, a packaging error occurred due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration as well.
This issue is Fedora-specific and affected Fedora 26, 27 and Rawhide. The affected downstream version is pure-ftpd-1.0.46-1.
Affected Software
Event History
Frequently Asked Questions
What are the security implications of REDHAT-BUG-1493114?
The security implications include the service running with default configurations that may override previously set security-related configurations.
How do I mitigate the risk associated with REDHAT-BUG-1493114?
You can mitigate the risk by reapplying your original configuration settings manually after the update.
Which versions of pure-ftpd are affected by REDHAT-BUG-1493114?
The affected versions include pure-ftpd version 1.0.46-1 in Fedora 26, 27, and Rawhide.
What Fedora releases are impacted by REDHAT-BUG-1493114?
The impacted Fedora releases are Fedora 26, Fedora 27, and the Rawhide version.
Is there a fix available for REDHAT-BUG-1493114?
As of now, the recommended fix involves manually configuring the service back to the desired settings after the update.