- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Hilmar Preusse
- Date:
- 2026-09-12 08:07:27 UTC
- Severity:
- normal
- Tags:
(Please provide enough information to help the release team to judge the request efficiently. E.g. by filling in the sections below.) [ Reason ] There were a few security leaks recently discovered in the proftp code. This update addresses these leaks (see below in [Changes]). [ Impact ] If the update is not approved, the existing proftp installations will further suffer from the security leaks in question. [ Tests ] The proftp package has an automated test suite, which runs successful even after applying the pataches. [ Risks ] See tests. [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in stable [X] the issue is verified as fixed in unstable [ Changes ] The update contains the 4 patches to address CVE-2026-44331 / CVE-2026-53994 / CVE-2026-63091 / CVE-2026-63090 [ Other info ] N/A.
package release.debian.org tags 1142828 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: proftpd-dfsg Version: 1.3.8.c+dfsg-4+deb13u3 Explanation: fix SQL injection issue [CVE-2026-44331]; fix buffer overflow issues [CVE-2026-53994 CVE-2026-63090]; fix integer overflow issue [CVE-2026-63091]
package release.debian.org tags 1142828 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: proftpd-dfsg Version: 1.3.8.c+dfsg-4+deb13u3 Explanation: fix SQL injection issue [CVE-2026-44331]; fix buffer overflow issues [CVE-2026-53994 CVE-2026-63090]; fix integer overflow issue [CVE-2026-63091]
This update was released as part of 13.7.