[ProFTPD-announce] ProFTPD 1.3.3d

Meesterlijk

Verified User
Joined
Jan 19, 2007
Messages
179
Location
Netherlands
Hello, ProFTPD community. The ProFTPD Project team is pleased to announce
that the fourth maintenance release for ProFTPD 1.3.3 is now available for
public consumption.

You can download 1.3.3d, including PGP signatures and MD5 sums, from any
of the proftpd mirrors. Mirrors are available via FTP as:

ftp.<two_letter_iso_country_code>.proftpd.org

(example: ftp.nl.proftpd.org). Not all countries have mirrors; however
you should select one that is geographically close to you.

Alternatively, you can download proftpd from the main site:

ftp://ftp.proftpd.org/distrib/source

RPMs, once available, will be placed here:

ftp://ftp.proftpd.org/distrib/packages/RPMS

The 1.3.3d release is a maintenance and security release. It contains
fixes for sql_prepare_where() buffer overflow (Bug#3536), and other
bugfixes.

Please read the included NEWS, RELEASE_NOTES, and ChangeLog files for
the full details.

The MD5 sums for the source tarballs are:

69650e91e05b3a10fa3ac54ee261679b proftpd-1.3.3d.tar.bz2
72c8368b947500995c3e5fc098d0241d proftpd-1.3.3d.tar.gz

The PGP signatures for the source tarballs are:

proftpd-1.3.3d.tar.bz2:

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAk0MBwIACgkQt46JP6URl2q5WgCfYrhQrxRvvCLOx+IuYjA0YdNW
vXYAoJEGHdRl8BPDqAUahZGcSx3Znpru
=Wy/N
-----END PGP SIGNATURE-----

proftpd-1.3.3d.tar.gz:

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAk0MBwcACgkQt46JP6URl2rdkgCgu88S30olDrmuYgfDiQdvOthh
VJYAoN436UroBHYRYyMtbB9KOpg/NtGK
=Fc2V
-----END PGP SIGNATURE-----

My PGP key has been used to sign the source tarballs as well as this
announcement; it is available via MIT's public keyserver.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAk0MB80ACgkQt46JP6URl2qWKACguwHD9o77qv4Uvfb2SQxX+pO2
/NEAn0/GrZ3VsdXpJ0JuRVYxECUuAD6v
=SoAU
-----END PGP SIGNATURE-----
 
Thanks!

We've updated our servers without any problem:

Code:
cd /usr/local/directadmin/custombuild && ./build clean && ./build update
./build proftpd

Changes from 1.3.3c to 1.3.3d:

1.3.3d
---------

+ Fixed sql_prepare_where() buffer overflow (Bug#3536)
+ Fixed CPU spike when handling .ftpaccess files.
+ Fixed handling of SFTP uploads when compression is used.
 
Just a quick note to let you know that the chained certificate bug is still there, you need to patch this release or upgrade to 1.3.4 to have proper validation.
 
Back
Top