[El-errata] ELSA-2010-0585 Moderate: Enterprise Linux 5 lftp security update

Errata Announcements for Enterprise Linux el-errata at oss.oracle.com
Mon Aug 2 19:56:39 PDT 2010


Enterprise Linux Security Advisory ELSA-2010-0585

https://rhn.redhat.com/errata/RHSA-2010-0585.html

The following updated rpms for Enterprise Linux 5 have been uploaded to 
the Unbreakable Linux Network:

i386:
lftp-3.7.11-4.el5_5.3.i386.rpm

x86_64:
lftp-3.7.11-4.el5_5.3.x86_64.rpm

ia64:
lftp-3.7.11-4.el5_5.3.ia64.rpm


SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/lftp-3.7.11-4.el5_5.3.src.rpm


Description of changes:


[3.7.11-4.el5_5.3]
- Related: CVE-2010-2251 - document change of xfer:clobber default
  value in manpage, respect xfer:clobber on with xfer:auto-rename on
  (old behaviour)

[3.7.11-4.el5_5.2]
- Related: CVE-2010-2251 - describe new option xfer:auto-rename
  which could restore old behaviour in manpage

[3.7.11-4.el5_5.1]
- Resolves: CVE-2010-2251 - multiple HTTP client download filename
  vulnerability (#617870)





More information about the El-errata mailing list