proftpd-1.3.8d-4.el9
- proftpd-1.3.8d-4.el9
This update contains backported fixes for a number of security issues, largely relating to features that are not enabled by default such as SFTP and SQL support. The exception is the addition of mod_procfs, enabled by default, which blocks accesses to procfs filesystems and hence prevents ACL bypasses via the use of the /proc/self/root directory; note that access to /proc is normally blocked via the default use of the DefaultRoot directive anyway.