Closing per note in our CVE tracker. If this is incorrect, please reopen:
stefanlsd> After discussion with Francesco Paolo Lovergine <email address hidden>
we concluded that this bug does not affect the Debian or Ubuntu versions of
proftpd 1.3.1 or earlier. We believe the problems that this CVE affects were only
introduced in the proftpd 1.3.2rc series. The exploit as found in the Bugs section
was independently tested and shown to not apply.
Closing per note in our CVE tracker. If this is incorrect, please reopen:
stefanlsd> After discussion with Francesco Paolo Lovergine <email address hidden>
we concluded that this bug does not affect the Debian or Ubuntu versions of
proftpd 1.3.1 or earlier. We believe the problems that this CVE affects were only
introduced in the proftpd 1.3.2rc series. The exploit as found in the Bugs section
was independently tested and shown to not apply.