openSUSE-RU-2013:0677-1: moderate: vsftpd: relax sandboxing to fix feature regressions
openSUSE Recommended Update: vsftpd: relax sandboxing to fix feature regressions ______________________________________________________________________________ Announcement ID: openSUSE-RU-2013:0677-1 Rating: moderate References: #786024 #812406 Affected Products: openSUSE 12.3 ______________________________________________________________________________ An update that has two recommended fixes can now be installed. Description: vsftpd confinement was too strict and adjusted to fix some lacking functionality: * drop CLONE_NEWPID from clone to enable audit system * unconditionally enable fcntl with F_SETFL * this enabled a sendto on /dev/log socket when syslog is enabled Patch Instructions: To install this openSUSE Recommended Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 12.3: zypper in -t patch openSUSE-2013-337 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 12.3 (i586 x86_64): vsftpd-3.0.2-4.5.1 vsftpd-debuginfo-3.0.2-4.5.1 vsftpd-debugsource-3.0.2-4.5.1 References: https://bugzilla.novell.com/786024 https://bugzilla.novell.com/812406
participants (1)
-
maintenance@opensuse.org