|
|
Message-ID: <52cfdf6a-d4ee-40ec-9d64-e28b8f81132e@oracle.com>
Date: Fri, 1 May 2026 09:13:17 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2026-42167: SQL injection in ProFTPd prior to
1.3.9a
On 5/1/26 02:25, Valtteri Vuorikoski wrote:
> The official site <https://www.proftpd.org> seems to be down at the moment so I
> don't know if or how this has been officially announced.
It is listed in the NEWS filed for the 1.3.9a release on their github repo:
https://github.com/proftpd/proftpd/blob/1.3.9/NEWS
The bug report is also visible there:
https://github.com/proftpd/proftpd/issues/2052
--
-Alan Coopersmith- alan.coopersmith@...cle.com
Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.