CVE-2015-1419

NameCVE-2015-1419
DescriptionUnspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs776922

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vsftpd (PTS)jessie3.0.2-17+deb8u1fixed
stretch3.0.3-8fixed
buster, bullseye3.0.3-12fixed
bookworm3.0.3-13fixed
sid, trixie3.0.3-13.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vsftpdsourcejessie3.0.2-17+deb8u1
vsftpdsource(unstable)3.0.2-18unimportant776922

Notes

http://seclists.org/oss-sec/2015/q1/389
Not a real security feature according the manpage and upstream

Search for package or bug name: Reporting problems