proftpd: ignore CVE-2021-47865

Details: https://nvd.nist.gov/vuln/detail/CVE-2021-47865

This CVE was opened based on a 5 years old Github issue[1], and has been made
public recently. The CVE wasn't officially disputed (yet?), but based on
the description and the given PoC the application is working as expected.

The vulnerability description and the PoC basically configures proftpd to
accept maximum x connections, and then when the user tries to open x + 1
concurrent connections, it refuses new connections over the configured limit.

See also discussion in the Github issue.

I just put it on the ignore list.

[1]: https://github.com/proftpd/proftpd/issues/1298

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
This commit is contained in:
Gyorgy Sarvari 2026-01-28 06:51:18 +01:00
parent 510ac35c7d
commit 8c092c4a82

View File

@ -28,6 +28,9 @@ inherit autotools-brokensep useradd update-rc.d systemd multilib_script
# fixed-version: version 1.2.0rc3 removed affected module
CVE_CHECK_IGNORE += "CVE-2001-0027"
# the issue is not a vulnerability, works as expected
CVE_CHECK_IGNORE += "CVE-2021-47865"
PACKAGECONFIG ??= "shadow \
${@bb.utils.filter('DISTRO_FEATURES', 'ipv6 pam', d)} \
static \