[CVE-2011-4130] Use-after-free issue

Related Vulnerabilities: CVE-2011-4130   CVE-2011-0411  

Debian Bug report logs - #648373
[CVE-2011-4130] Use-after-free issue

version graph

Reported by: Florian Weimer <fw@deneb.enyo.de>

Date: Thu, 10 Nov 2011 20:33:02 UTC

Severity: grave

Tags: patch, security

Found in version 1.3.3a-6squeeze1

Fixed in versions proftpd-dfsg/1.3.4~rc3-2, proftpd-dfsg/1.3.3a-6squeeze4

Done: Francesco Paolo Lovergine <frankie@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>:
Bug#648373; Package proftpd-dfsg. (Thu, 10 Nov 2011 20:33:05 GMT) (full text, mbox, link).


Acknowledgement sent to Florian Weimer <fw@deneb.enyo.de>:
New Bug report received and forwarded. Copy sent to ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>. (Thu, 10 Nov 2011 20:33:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Florian Weimer <fw@deneb.enyo.de>
To: submit@bugs.debian.org
Subject: [CVE-2011-4130] Use-after-free issue
Date: Thu, 10 Nov 2011 21:31:17 +0100
Package: proftpd-dfsg
Version: 1.3.3a-6squeeze1
Severity: grave
Tags: security

A use-after-free issue has been discovered in ProFTPd:

<http://bugs.proftpd.org/show_bug.cgi?id=3711>

It seems that squeeze is vulnerable, too.  I haven't checked the code
in lenny yet.




Added tag(s) pending. Request was from "Francesco P. Lovergine" <frankie@debian.org> to control@bugs.debian.org. (Fri, 11 Nov 2011 11:57:02 GMT) (full text, mbox, link).


Added tag(s) patch. Request was from "Francesco P. Lovergine" <frankie@debian.org> to control@bugs.debian.org. (Fri, 11 Nov 2011 11:57:03 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>:
Bug#648373; Package proftpd-dfsg. (Fri, 11 Nov 2011 12:51:04 GMT) (full text, mbox, link).


Acknowledgement sent to "Francesco P. Lovergine" <frankie@debian.org>:
Extra info received and forwarded to list. Copy sent to ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>. (Fri, 11 Nov 2011 12:51:10 GMT) (full text, mbox, link).


Message #14 received at 648373@bugs.debian.org (full text, mbox, reply):

From: "Francesco P. Lovergine" <frankie@debian.org>
To: Florian Weimer <fw@deneb.enyo.de>, 648373@bugs.debian.org
Cc: team@security.debian.org
Subject: Re: Bug#648373: [CVE-2011-4130] Use-after-free issue
Date: Fri, 11 Nov 2011 12:54:58 +0100
[Message part 1 (text/plain, inline)]
tag 648373 + pending
tag 648373 + patch
thanks

On Thu, Nov 10, 2011 at 09:31:17PM +0100, Florian Weimer wrote:
> Package: proftpd-dfsg
> Version: 1.3.3a-6squeeze1
> Severity: grave
> Tags: security
> 
> A use-after-free issue has been discovered in ProFTPd:
> 
> <http://bugs.proftpd.org/show_bug.cgi?id=3711>
> 
> It seems that squeeze is vulnerable, too.  I haven't checked the code
> in lenny yet.
> 

I have 1.3.3a-6squeeze3 ready for squeeze with the required fix. 
Waiting for a secteam go signal, just in case.

-- 
Francesco P. Lovergine
[3711.dpatch (text/plain, attachment)]
[signature.asc (application/pgp-signature, inline)]

Reply sent to Francesco Paolo Lovergine <frankie@debian.org>:
You have taken responsibility. (Fri, 11 Nov 2011 12:51:33 GMT) (full text, mbox, link).


Notification sent to Florian Weimer <fw@deneb.enyo.de>:
Bug acknowledged by developer. (Fri, 11 Nov 2011 12:51:35 GMT) (full text, mbox, link).


Message #19 received at 648373-close@bugs.debian.org (full text, mbox, reply):

From: Francesco Paolo Lovergine <frankie@debian.org>
To: 648373-close@bugs.debian.org
Subject: Bug#648373: fixed in proftpd-dfsg 1.3.4~rc3-2
Date: Fri, 11 Nov 2011 12:47:40 +0000
Source: proftpd-dfsg
Source-Version: 1.3.4~rc3-2

We believe that the bug you reported is fixed in the latest version of
proftpd-dfsg, which is due to be installed in the Debian FTP archive:

proftpd-basic_1.3.4~rc3-2_i386.deb
  to main/p/proftpd-dfsg/proftpd-basic_1.3.4~rc3-2_i386.deb
proftpd-dev_1.3.4~rc3-2_i386.deb
  to main/p/proftpd-dfsg/proftpd-dev_1.3.4~rc3-2_i386.deb
proftpd-dfsg_1.3.4~rc3-2.debian.tar.gz
  to main/p/proftpd-dfsg/proftpd-dfsg_1.3.4~rc3-2.debian.tar.gz
proftpd-dfsg_1.3.4~rc3-2.dsc
  to main/p/proftpd-dfsg/proftpd-dfsg_1.3.4~rc3-2.dsc
proftpd-doc_1.3.4~rc3-2_all.deb
  to main/p/proftpd-dfsg/proftpd-doc_1.3.4~rc3-2_all.deb
proftpd-mod-ldap_1.3.4~rc3-2_i386.deb
  to main/p/proftpd-dfsg/proftpd-mod-ldap_1.3.4~rc3-2_i386.deb
proftpd-mod-mysql_1.3.4~rc3-2_i386.deb
  to main/p/proftpd-dfsg/proftpd-mod-mysql_1.3.4~rc3-2_i386.deb
proftpd-mod-odbc_1.3.4~rc3-2_i386.deb
  to main/p/proftpd-dfsg/proftpd-mod-odbc_1.3.4~rc3-2_i386.deb
proftpd-mod-pgsql_1.3.4~rc3-2_i386.deb
  to main/p/proftpd-dfsg/proftpd-mod-pgsql_1.3.4~rc3-2_i386.deb
proftpd-mod-sqlite_1.3.4~rc3-2_i386.deb
  to main/p/proftpd-dfsg/proftpd-mod-sqlite_1.3.4~rc3-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 648373@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Francesco Paolo Lovergine <frankie@debian.org> (supplier of updated proftpd-dfsg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Fri, 11 Nov 2011 13:19:37 +0100
Source: proftpd-dfsg
Binary: proftpd-basic proftpd-dev proftpd-doc proftpd-mod-mysql proftpd-mod-pgsql proftpd-mod-ldap proftpd-mod-odbc proftpd-mod-sqlite
Architecture: source i386 all
Version: 1.3.4~rc3-2
Distribution: unstable
Urgency: high
Maintainer: ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>
Changed-By: Francesco Paolo Lovergine <frankie@debian.org>
Description: 
 proftpd-basic - Versatile, virtual-hosting FTP daemon - binaries
 proftpd-dev - Versatile, virtual-hosting FTP daemon - development files
 proftpd-doc - Versatile, virtual-hosting FTP daemon - documentation
 proftpd-mod-ldap - Versatile, virtual-hosting FTP daemon - LDAP module
 proftpd-mod-mysql - Versatile, virtual-hosting FTP daemon - MySQL module
 proftpd-mod-odbc - Versatile, virtual-hosting FTP daemon - ODBC module
 proftpd-mod-pgsql - Versatile, virtual-hosting FTP daemon - PostgreSQL module
 proftpd-mod-sqlite - Versatile, virtual-hosting FTP daemon - SQLite3 module
Closes: 648373
Changes: 
 proftpd-dfsg (1.3.4~rc3-2) unstable; urgency=high
 .
   * Added libacl1-dev and libssl-dev to proftpd-dev dependencies, due to
     header files inclusion.
   * Added patch 3711 to manage CVE-2011-4130 (Response pool use-after-free
     memory corruption error).
     (closes: #648373)
Checksums-Sha1: 
 8603692bbe7714c44ef60f084d5fddf0fc3ede1b 1933 proftpd-dfsg_1.3.4~rc3-2.dsc
 811a2e7c944caef6945ecfe4fa73217973539ff5 95813 proftpd-dfsg_1.3.4~rc3-2.debian.tar.gz
 9533ab968b729c72ce7cbf38abefb25577f78a33 2501676 proftpd-basic_1.3.4~rc3-2_i386.deb
 31822a3719bf4411f564dda8d7d706b93a670a4c 956166 proftpd-dev_1.3.4~rc3-2_i386.deb
 b3d2a1435eb082d9cb265c07da0a5c5e9451c341 395878 proftpd-mod-mysql_1.3.4~rc3-2_i386.deb
 798c176dbedb579260b32e9e45f9959375f0bc40 395728 proftpd-mod-pgsql_1.3.4~rc3-2_i386.deb
 2446e8637c17b66da8abb2b158e71d0f9270b75e 404004 proftpd-mod-ldap_1.3.4~rc3-2_i386.deb
 1ae72c374b004efc4907988b90d535a677618941 397098 proftpd-mod-odbc_1.3.4~rc3-2_i386.deb
 24f66d189d8028964a4f77927cc4de1de9c35322 395248 proftpd-mod-sqlite_1.3.4~rc3-2_i386.deb
 19493bebed53c02b27458d89772a79e5ff5da64f 1607688 proftpd-doc_1.3.4~rc3-2_all.deb
Checksums-Sha256: 
 a1ffec4021bde2d178697fc7fab1f12d155eef8b09083c46117a35e405e6fac9 1933 proftpd-dfsg_1.3.4~rc3-2.dsc
 c548b3c2710e3d3041814ee2bf61d7545392713fd06c5b1676c28633dd12d37d 95813 proftpd-dfsg_1.3.4~rc3-2.debian.tar.gz
 e52ed7afdea4a5193904e228a12bc004fa67d9ca7fa7ae7614b64154dcd81b32 2501676 proftpd-basic_1.3.4~rc3-2_i386.deb
 58149332745c6f42687229521d25e2d0daf29ef4d2c5661a026743418fbddbd5 956166 proftpd-dev_1.3.4~rc3-2_i386.deb
 e70608d3c44f3e11fc9f43bf648ead11f5b0f775e8861fa21549a4c9b36dd7b2 395878 proftpd-mod-mysql_1.3.4~rc3-2_i386.deb
 1331d9d6166c0183165c7a2f5f1d3bed99b571c160ed429e3973deb64693a066 395728 proftpd-mod-pgsql_1.3.4~rc3-2_i386.deb
 b3f68ab506001422f9dd8b9e67cf3693df7bad162a5d1a8b8140ec95f7801213 404004 proftpd-mod-ldap_1.3.4~rc3-2_i386.deb
 4aefaaf3b876ade5d048ed21b8c4609a84ac1cd1cba2459f60ea6f024c1e39f1 397098 proftpd-mod-odbc_1.3.4~rc3-2_i386.deb
 6cb02ace3827d9f38e29e43aa2e57d280fcf9b843a2747b9757b13c2f8964c6d 395248 proftpd-mod-sqlite_1.3.4~rc3-2_i386.deb
 4a79956016274dd6fd4e58eae43ee87196e23a32f0248212d04cccdeb65ed4f4 1607688 proftpd-doc_1.3.4~rc3-2_all.deb
Files: 
 d2dacf45b83b5182a7ad2b54d1a63b8a 1933 net optional proftpd-dfsg_1.3.4~rc3-2.dsc
 3461a6655038ce71cc6f654972ce2dfd 95813 net optional proftpd-dfsg_1.3.4~rc3-2.debian.tar.gz
 3bb79708a202093f058c73bcd8a43df2 2501676 net optional proftpd-basic_1.3.4~rc3-2_i386.deb
 171281dddb0838f419d47e3f8e01354a 956166 net optional proftpd-dev_1.3.4~rc3-2_i386.deb
 a1df89b077c25ca2c3cc3b3c8fbd6795 395878 net optional proftpd-mod-mysql_1.3.4~rc3-2_i386.deb
 8bfa46c447cdeec02529ba711b5f598c 395728 net optional proftpd-mod-pgsql_1.3.4~rc3-2_i386.deb
 f96aa05c4dcec0188b2b86eadf93496b 404004 net optional proftpd-mod-ldap_1.3.4~rc3-2_i386.deb
 4ea9b5501b02296173d09096689a75f1 397098 net optional proftpd-mod-odbc_1.3.4~rc3-2_i386.deb
 8900e29cb3862c8bc16a6b90994cba34 395248 net optional proftpd-mod-sqlite_1.3.4~rc3-2_i386.deb
 6ddc2c8fbbe752c72aa67f11814ab583 1607688 doc optional proftpd-doc_1.3.4~rc3-2_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk69FboACgkQpFNRmenyx0eKcQCfUlVNfUGbsCHR97H3y0IIs3RP
jakAoPR8x+GfzBNYKpyt3Rv3C4zv1+i2
=ZRzF
-----END PGP SIGNATURE-----





Information forwarded to debian-bugs-dist@lists.debian.org, ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>:
Bug#648373; Package proftpd-dfsg. (Fri, 11 Nov 2011 18:57:05 GMT) (full text, mbox, link).


Acknowledgement sent to Florian Weimer <fw@deneb.enyo.de>:
Extra info received and forwarded to list. Copy sent to ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>. (Fri, 11 Nov 2011 18:57:05 GMT) (full text, mbox, link).


Message #24 received at 648373@bugs.debian.org (full text, mbox, reply):

From: Florian Weimer <fw@deneb.enyo.de>
To: "Francesco P. Lovergine" <frankie@debian.org>
Cc: 648373@bugs.debian.org, team@security.debian.org
Subject: Re: Bug#648373: [CVE-2011-4130] Use-after-free issue
Date: Fri, 11 Nov 2011 19:56:02 +0100
* Francesco P. Lovergine:

>> A use-after-free issue has been discovered in ProFTPd:
>> 
>> <http://bugs.proftpd.org/show_bug.cgi?id=3711>
>> 
>> It seems that squeeze is vulnerable, too.  I haven't checked the code
>> in lenny yet.

> I have 1.3.3a-6squeeze3 ready for squeeze with the required fix. 
> Waiting for a secteam go signal, just in case.

Thanks.  I trust that the call is at the right place, I find the code
somewhat confusing.

Please upload with the usual caveats (1.3.3a-6squeeze2 as version
number, squeeze-security suite, host security-master).




Information forwarded to debian-bugs-dist@lists.debian.org, ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>:
Bug#648373; Package proftpd-dfsg. (Fri, 11 Nov 2011 23:39:03 GMT) (full text, mbox, link).


Acknowledgement sent to "Francesco P. Lovergine" <frankie@debian.org>:
Extra info received and forwarded to list. Copy sent to ProFTPD Maintainance Team <pkg-proftpd-maintainers@lists.alioth.debian.org>. (Fri, 11 Nov 2011 23:39:03 GMT) (full text, mbox, link).


Message #29 received at 648373@bugs.debian.org (full text, mbox, reply):

From: "Francesco P. Lovergine" <frankie@debian.org>
To: Florian Weimer <fw@deneb.enyo.de>
Cc: "Francesco P. Lovergine" <frankie@debian.org>, 648373@bugs.debian.org, team@security.debian.org
Subject: Re: Bug#648373: [CVE-2011-4130] Use-after-free issue
Date: Sat, 12 Nov 2011 00:18:16 +0100
On Fri, Nov 11, 2011 at 07:56:02PM +0100, Florian Weimer wrote:
> * Francesco P. Lovergine:
> 
> >> A use-after-free issue has been discovered in ProFTPd:
> >> 
> >> <http://bugs.proftpd.org/show_bug.cgi?id=3711>
> >> 
> >> It seems that squeeze is vulnerable, too.  I haven't checked the code
> >> in lenny yet.
> 
> > I have 1.3.3a-6squeeze3 ready for squeeze with the required fix. 
> > Waiting for a secteam go signal, just in case.
> 
> Thanks.  I trust that the call is at the right place, I find the code
> somewhat confusing.
> 
> Please upload with the usual caveats (1.3.3a-6squeeze2 as version
> number, squeeze-security suite, host security-master).

About lenny, it appears the 1.3.1 version still had not the feature
of dispatching control commands while data transfers are going on.
So the whole pool mechanism is not operational and the issue does not
apply at all.

-- 
Francesco P. Lovergine




Reply sent to Francesco Paolo Lovergine <frankie@debian.org>:
You have taken responsibility. (Fri, 18 Nov 2011 02:00:04 GMT) (full text, mbox, link).


Notification sent to Florian Weimer <fw@deneb.enyo.de>:
Bug acknowledged by developer. (Fri, 18 Nov 2011 02:00:04 GMT) (full text, mbox, link).


Message #34 received at 648373-close@bugs.debian.org (full text, mbox, reply):

From: Francesco Paolo Lovergine <frankie@debian.org>
To: 648373-close@bugs.debian.org
Subject: Bug#648373: fixed in proftpd-dfsg 1.3.3a-6squeeze4
Date: Fri, 18 Nov 2011 01:57:38 +0000
Source: proftpd-dfsg
Source-Version: 1.3.3a-6squeeze4

We believe that the bug you reported is fixed in the latest version of
proftpd-dfsg, which is due to be installed in the Debian FTP archive:

proftpd-basic_1.3.3a-6squeeze4_amd64.deb
  to main/p/proftpd-dfsg/proftpd-basic_1.3.3a-6squeeze4_amd64.deb
proftpd-dev_1.3.3a-6squeeze4_amd64.deb
  to main/p/proftpd-dfsg/proftpd-dev_1.3.3a-6squeeze4_amd64.deb
proftpd-dfsg_1.3.3a-6squeeze4.diff.gz
  to main/p/proftpd-dfsg/proftpd-dfsg_1.3.3a-6squeeze4.diff.gz
proftpd-dfsg_1.3.3a-6squeeze4.dsc
  to main/p/proftpd-dfsg/proftpd-dfsg_1.3.3a-6squeeze4.dsc
proftpd-doc_1.3.3a-6squeeze4_all.deb
  to main/p/proftpd-dfsg/proftpd-doc_1.3.3a-6squeeze4_all.deb
proftpd-mod-ldap_1.3.3a-6squeeze4_amd64.deb
  to main/p/proftpd-dfsg/proftpd-mod-ldap_1.3.3a-6squeeze4_amd64.deb
proftpd-mod-mysql_1.3.3a-6squeeze4_amd64.deb
  to main/p/proftpd-dfsg/proftpd-mod-mysql_1.3.3a-6squeeze4_amd64.deb
proftpd-mod-odbc_1.3.3a-6squeeze4_amd64.deb
  to main/p/proftpd-dfsg/proftpd-mod-odbc_1.3.3a-6squeeze4_amd64.deb
proftpd-mod-pgsql_1.3.3a-6squeeze4_amd64.deb
  to main/p/proftpd-dfsg/proftpd-mod-pgsql_1.3.3a-6squeeze4_amd64.deb
proftpd-mod-sqlite_1.3.3a-6squeeze4_amd64.deb
  to main/p/proftpd-dfsg/proftpd-mod-sqlite_1.3.3a-6squeeze4_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 648373@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Francesco Paolo Lovergine <frankie@debian.org> (supplier of updated proftpd-dfsg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 13 Nov 2011 23:17:40 +0100
Source: proftpd-dfsg
Binary: proftpd-basic proftpd-dev proftpd-doc proftpd-mod-mysql proftpd-mod-pgsql proftpd-mod-ldap proftpd-mod-odbc proftpd-mod-sqlite
Architecture: source amd64 all
Version: 1.3.3a-6squeeze4
Distribution: stable-security
Urgency: low
Maintainer: Francesco Paolo Lovergine <frankie@debian.org>
Changed-By: Francesco Paolo Lovergine <frankie@debian.org>
Description: 
 proftpd-basic - Versatile, virtual-hosting FTP daemon - binaries
 proftpd-dev - Versatile, virtual-hosting FTP daemon - development files
 proftpd-doc - Versatile, virtual-hosting FTP daemon - documentation
 proftpd-mod-ldap - Versatile, virtual-hosting FTP daemon - LDAP module
 proftpd-mod-mysql - Versatile, virtual-hosting FTP daemon - MySQL module
 proftpd-mod-odbc - Versatile, virtual-hosting FTP daemon - ODBC module
 proftpd-mod-pgsql - Versatile, virtual-hosting FTP daemon - PostgreSQL module
 proftpd-mod-sqlite - Versatile, virtual-hosting FTP daemon - SQLite3 module
Closes: 648373
Changes: 
 proftpd-dfsg (1.3.3a-6squeeze4) stable-security; urgency=low
 .
   * [SECURITY] 3711.dpatch. This patch fixes a response pool use-after-free
     memory corruption error. This is CVE-2011-4130.
     (closes: #648373)
   * [SECURITY] 3624.dpatch This patch fixes the issue by causing mod_tls to
     clear the buffers of any data received from the client, once the SSL/TLS
     handshake has succeded. This is similar to CVE-2011-0411.
Checksums-Sha1: 
 ec267578b10cf9d6bc8a4530475e843dfd95944a 1426 proftpd-dfsg_1.3.3a-6squeeze4.dsc
 77fc5a4f580ef1058ff65efd3cdc70e1253259ee 108182 proftpd-dfsg_1.3.3a-6squeeze4.diff.gz
 2bb34561a039215ea11cff34ee3268dc12f4314d 2404094 proftpd-basic_1.3.3a-6squeeze4_amd64.deb
 639d175827dd98d8f9d948f5bc36eee3eef3ade6 889434 proftpd-dev_1.3.3a-6squeeze4_amd64.deb
 24c56111e8f630e591fe989801fb2718dfcecb26 346766 proftpd-mod-mysql_1.3.3a-6squeeze4_amd64.deb
 b04e399315ed46aa1c56e66358f9e0748812441d 346460 proftpd-mod-pgsql_1.3.3a-6squeeze4_amd64.deb
 6ff8aa6b9835f601cbea97306c91cd2c79f0b0f2 356368 proftpd-mod-ldap_1.3.3a-6squeeze4_amd64.deb
 0aafd36b9de917652d76f505db548abff97b73df 348098 proftpd-mod-odbc_1.3.3a-6squeeze4_amd64.deb
 f6d9f188145de28b19047de0f2eb97a8fea33aef 345812 proftpd-mod-sqlite_1.3.3a-6squeeze4_amd64.deb
 f562db641c3b62d78607c12c8d02246a79453706 1508134 proftpd-doc_1.3.3a-6squeeze4_all.deb
Checksums-Sha256: 
 78b1d27e6e274a62bf7991ad97563026ebb34b563059fce886e6ed799a963d7e 1426 proftpd-dfsg_1.3.3a-6squeeze4.dsc
 719326db8ac471e1caf1c534aeb5d5da5baa323659582270ac7f1074fc89ed88 108182 proftpd-dfsg_1.3.3a-6squeeze4.diff.gz
 6d3193773f15687e79596e7fdc77b20b6f1258688a0682f2d1438eb1c35354e5 2404094 proftpd-basic_1.3.3a-6squeeze4_amd64.deb
 fb43302e6c0c4e5f0467e022e74e2cdc229eb39dbe2a36b52fadaac0d3679121 889434 proftpd-dev_1.3.3a-6squeeze4_amd64.deb
 0723b60e23e906fe3d20a1926425bf1d364ba333638835710e2d5a808cd08061 346766 proftpd-mod-mysql_1.3.3a-6squeeze4_amd64.deb
 699b78ffef8989c09328fee992d1d8b298f18099d61674aafc535f17ab17fcef 346460 proftpd-mod-pgsql_1.3.3a-6squeeze4_amd64.deb
 f18db91364fb224c57845453b68595f230cf0687c2b26fe08a2cfc394ebd36cc 356368 proftpd-mod-ldap_1.3.3a-6squeeze4_amd64.deb
 1b28312578e66c47f8c1d23a0d271384ccfb09457f9677886d8f43a503ae6995 348098 proftpd-mod-odbc_1.3.3a-6squeeze4_amd64.deb
 a5edfc13235c1ce1f853501302a527962584306855426d4a4d39cf9132f20c9a 345812 proftpd-mod-sqlite_1.3.3a-6squeeze4_amd64.deb
 ee95291ecd3f141f06b57e68f0a358b96b8990be376c92f28aa7aeddc157fdae 1508134 proftpd-doc_1.3.3a-6squeeze4_all.deb
Files: 
 9413b160e117caf0ce596be1097318aa 1426 net optional proftpd-dfsg_1.3.3a-6squeeze4.dsc
 cb160663d3a546eab13b24459899a52e 108182 net optional proftpd-dfsg_1.3.3a-6squeeze4.diff.gz
 585ab2c70be0387a29d049a1d1a57ae1 2404094 net optional proftpd-basic_1.3.3a-6squeeze4_amd64.deb
 dc024acfcd4f39deca0f629808c9aa0a 889434 net optional proftpd-dev_1.3.3a-6squeeze4_amd64.deb
 5b62dcf505d01e55834eea4811cc46eb 346766 net optional proftpd-mod-mysql_1.3.3a-6squeeze4_amd64.deb
 3b9d79f9960f127f1c3d2275b3551547 346460 net optional proftpd-mod-pgsql_1.3.3a-6squeeze4_amd64.deb
 6d9ee226da8c02b88fa0528e582452b4 356368 net optional proftpd-mod-ldap_1.3.3a-6squeeze4_amd64.deb
 c127b01d43516a0f4a719c96d9b88273 348098 net optional proftpd-mod-odbc_1.3.3a-6squeeze4_amd64.deb
 577c0f5d16222bc1889d0ec690d4d05a 345812 net optional proftpd-mod-sqlite_1.3.3a-6squeeze4_amd64.deb
 cb642939f5b69a544fce7057da69a41f 1508134 doc optional proftpd-doc_1.3.3a-6squeeze4_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk7ASFkACgkQpFNRmenyx0e5nQCcCvwNiDQ6jMyjfe/wonrw5nye
LWYAoIZoZiBBPqcC31KroaSvdGHiZNSg
=if7l
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 29 Jan 2012 07:38:05 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 19:15:57 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.