REDHAT-BUG-815188: Medium severity vsftpd vulnerability
Vadim Ponomarev (ccrssaa at karelia.ru), report a pid namespace leak caused by vsftpd.
Detailed discussion can be found in: https://bugzilla.novell.com/showbug.cgi?id=757783
Introduced by: http://git.kernel.org/linus/423e0ab086ad8b33626e45fa94ac7613146b7ffa
Upstream commit: http://git.kernel.org/linus/905ad269c55fc62bee3da29f7b1d1efeba8aa1e1
Steps to reproduce: https://bugzilla.novell.com/showbug.cgi?id=757783#c0
Acknowledgements:
Red Hat would like to thank Vadim Ponomarev for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-815188?
The severity of REDHAT-BUG-815188 is considered medium due to the potential for a pid namespace leak.
How do I fix REDHAT-BUG-815188?
To fix REDHAT-BUG-815188, update vsftpd to the latest available version provided by the vendor.
What causes the vulnerability REDHAT-BUG-815188?
The vulnerability REDHAT-BUG-815188 is caused by a flaw in the vsftpd that leads to a namespace leak.
Is REDHAT-BUG-815188 being actively addressed?
Yes, REDHAT-BUG-815188 is being addressed through patches and updates from the vsftpd maintainers.
Who reported the vulnerability REDHAT-BUG-815188?
The vulnerability REDHAT-BUG-815188 was reported by Vadim Ponomarev.