[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-35025/proftpd-dfsg

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 21:38:33 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b0ecacb9 by Salvatore Bonaccorso at 2026-07-26T22:32:39+02:00
Update status for CVE-2026-35025/proftpd-dfsg

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -28183,9 +28183,13 @@ CVE-2026-42450 (OpenColorIO is a color management framework for visual effects a
 	[bullseye] - opencolorio <not-affected> (Vulnerable code introduced in 2.x rewrite; 1.1.1 Spi3D parser scans %f directly, no %s into stack buffers)
 	NOTE: https://github.com/AcademySoftwareFoundation/OpenColorIO/security/advisories/GHSA-rxp3-rrgx-f547
 CVE-2026-35025 (ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass ...)
-	- proftpd-dfsg <unfixed>
+	- proftpd-dfsg <unfixed> (unimportant)
 	[trixie] - proftpd-dfsg <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/proftpd/proftpd/issues/2170
+	NOTE: Negligible impact, upstream does not want to make a special/edge case for /proc
+	NOTE: access in core ProFTPD code. Instead a new mod_procfs module is introduced,
+	NOTE: wich rejects commands which refer to paths in /proc, cf.
+	NOTE: https://github.com/proftpd/proftpd/issues/2170#issuecomment-4998331303
 CVE-2026-29034
 	REJECTED
 CVE-2026-13164 (Missing Authentication for Critical Function (CWE-306) in the Register ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0ecacb969cb3d04304b88311b173ebfe043b1e6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0ecacb969cb3d04304b88311b173ebfe043b1e6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/f9eb7238/attachment.htm>


More information about the debian-security-tracker-commits mailing list