Pardus: 2011-91: lftp: MITM
Posted by Benjamin D. Thomas   
A vulnerability has been fixed in lftp.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2011-91            security@pardus.org.tr
------------------------------------------------------------------------
      Date: 2011-07-06
      Type: Remote
------------------------------------------------------------------------

Summary
======
A vulnerability has been fixed in lftp.


Description
==========
lftp   up to   and   including   version   4.1.3   has   an    option
"ssl:verify-certificate" which unfortunatly defaults  to  "no".  Ie  no
certificate checks. Moreover, when compiled with  openssl  rather  than
gnutls lftp does not turn off SSLv2 (bad for openssl pre 1.0) and

lacks code to actually verify the hostname. Ie it's prone to MITM.


Affected packages:

  Pardus 2009:
    lftp, all before 4.2.2-6-6


Resolution
=========
There are update(s) for lftp. You can update them via Package Manager or
with a single command from console:

    pisi up lftp

References
=========
  * http://bugs.pardus.org.tr/show_bug.cgi?id993

------------------------------------------------------------------------