Project Zero, probably the best technical security blog around: Project Zero blog
Follow me on Twitter for vsftpd / security news: scarybeasts
My security blog:
My security advisories:
Aug 2021 - vsftpd-3.0.4 / vsftpd-3.0.5 released with build, seccomp and SSL modernizationsvsftpd-3.0.5 fixes the new ALPN selection, so it works again with thelatest FileZilla client.
vsftpd-3.0.4 is released, 6 years after the previous release! This nowbuilds and runs again on a modern system such as Fedora 33 -- a few things hadbroken over the years. A few SSL modernizations have been applied, such asrequiring TLSv1.2+ by default, supporting ALPN, and optionally supporting anSNI check.See the Changelog andvsftpd FAQ (frequently asked questions) for a list of common questions!
This release is signed with my new RSA4096 scarybeasts@gmail.com GPG key(67A2 AB4F 41F9 972C 21F6 BF66 7B89 011B CAE1 CFEA):public key file
The release is also signed with my old chris@scary.beasts.org key for across check:release signature with old key
Here's a signature for my new GPG key, signed by my old key:signature for new public key, signed by old key
Jul 2015 - vsftpd-3.0.3 released with SSL fixes and security improvementsvsftpd-3.0.3 is released - with most of the changes being SSL related. Otherthan that, there some seccomp policy fixes and minor compatability fixes.Somes notes on the SSL fixes will be put on my blog shortly.See the Changelog andvsftpd FAQ (frequently asked questions) for a list of common questions!
Sep 2012 - vsftpd-3.0.2 released with seccomp sandbox fixesvsftpd-3.0.2 is released - the only noteworthy fixes are two seccomp sandboxpolicy tweaks which stops session crashes when listing large directories.See the Changelog andvsftpd FAQ (frequently asked questions) for a list of common questions!
Apr 2012 - vsftpd-3.0.0 released with a seccomp filter sandboxvsftpd-3.0.0 is released - with a new highly restrictive seccomp filtersandbox. It activates automatically on 64-bit bit binaries on Ubuntu 12.04+.In addition, there's a fix for passive mode connections under high loads anda few timeout fixes, particularly if you're using SSL.See the Changelog andvsftpd FAQ (frequently asked questions) for a list of common questions!
Dec 2011 - vsftpd-2.3.5 releasedvsftpd-2.3.5 is released - with a fix for active mode connection errorhandling and a workaround for a glibc vulnerability that may affect unusualconfigurations.See the Changelog andvsftpd FAQ (frequently asked questions) for a list of common questions!
Older:
After numerous requests, I now have a PayPal button for donations. If youuse vsftpd, like it, and think it's worthy of a donation, then click on thePaypal button on the left of the page.
ftp.freebsd.org switched to vsftpd.
vsftpd tarballs are now GPG signed by me (8660 FD32 91B1 84CD BC2F 6418 AA62 EC46 3C0E 751C)
Nov 2011 - Is any server other than vsftpd safe?ProFTPd suffers serious security hole - Nov 2011
ProFTPd suffers serious security hole - Sep 2003
wu-ftpd suffers serious security hole - Jul 2003.
lukemftpd (as a random example from many), via trust of realpath(), suffers serious security hole - Aug 2003.
ftp.redhat.com is powered by vsftpd for performance reasons - see below
Download Source Package filezilla: [filezilla_3.58.0-1.dsc]
[filezilla_3.58.0.orig.tar.bz2]
[filezilla_3.58.0-1.debian.tar.xz]
Maintainer: Ubuntu MOTU Developers (Mail Archive)
Please consider filing a bug or asking a question via Launchpad before contacting the maintainer directly.
FileZilla 3.0.0
Other Packages Related to filezilla depends
recommends
suggests
enhances
dep:filezilla-common (= 3.58.0-1) Architecture independent files for filezilla dep:libc6 (>= 2.34) GNU C Library: Shared libraries dep:libdbus-1-3 (>= 1.9.14) simple interprocess messaging system (library) dep:libfilezilla24 (>= 0.36.0) build high-performing platform-independent programs (runtime lib) dep:libgcc-s1 (>= 3.3.1) GCC support library dep:libgtk-3-0 (>= 3.0.0) GTK graphical user interface library dep:libnettle8 low level cryptographic library (symmetric and one-way cryptos) dep:libpugixml1v5 (>= 1.6) Light-weight C++ XML processing library dep:libsqlite3-0 (>= 3.5.9) SQLite 3 shared library dep:libstdc++6 (>= 11) GNU Standard C++ Library v3 dep:libwxbase3.0-0v5 (>= 3.0.5.1+dfsg) wxBase library (runtime) - non-GUI support classes of wxWidgets toolkit dep:libwxgtk3.0-gtk3-0v5 (>= 3.0.5.1+dfsg) wxWidgets Cross-platform C++ GUI toolkit (GTK 3 runtime) rec:xdg-utils desktop integration utilities from freedesktop.org Download filezilla Download for all available architectures ArchitecturePackage SizeInstalled SizeFiles ppc64el2,148.2 kB7,791.0 kB [list of files] This page is also available in the following languages:
Dvojica zaujímavých aplikácií sa objavila vo svojich nových finálnych verziách. Pod názvom FileZilla 3.0.0 vystupuje nová generácia FTP klienta s otvorenými zdrojovými kódmi. Primárnou novinkou verzie 3.0 je zaistenie fungovania aplikácie na mnohých platformách. Popri Windows aj na Linuxe, *BSD, Mac OS X. V čase písania článku už boli k stiahnutiu cez download stránku verzie pre Windows i Linux. 2ff7e9595c