Bug 30506

Summary: gFTP crashes
Product: Mageia Reporter: Franz Holzinger <flink>
Component: RPM PackagesAssignee: Jani Välimaa <jani.valimaa>
Status: NEW --- QA Contact:
Severity: major    
Priority: Normal    
Version: 8   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: gftp-2.0.19-23.mga8.src.rpm CVE:
Status comment:

Description Franz Holzinger 2022-06-03 22:16:09 CEST
When I connect to a server via FTPS, then immediately gFTP crashes.
Comment 1 Lewis Smith 2022-06-05 09:21:19 CEST
Please give some more information:

1. Launch gFTP from a terminal:
 $ gftp
and after the crash, post the output (use X copy/paste) here.

2. Can you say whether the crash happens also with just 'FTP' as well as 'FTPS'.

3. As below if you wish.

@bugsquad
Can someone with an FTP account somewhere try this? Or send me privately all the details of an account to try - that offers FTPS? (Host, port, username, password). I have looked around...

CC: (none) => lewyssmith

Comment 2 Franz Holzinger 2022-06-08 18:55:05 CEST
2. This error only happens with "FTPS'.
gFTP is just busy now and hangs in a rolling mouse cursor.


gFTP output:

gFTP 2.0.19, Copyright (C) 1998-2008 Brian Masney <masneyb@gftp.org>. If you have any questions, comments, or suggestions about this program, please feel free to email them to me. You can always find out the latest news about gFTP from my website at http://www.gftp.org/
gFTP comes with ABSOLUTELY NO WARRANTY; for details, see the COPYING file. This is free software, and you are welcome to redistribute it under certain conditions; for details, see the COPYING file
View: Not connected to a remote site
Looking up example.com
Trying example.com:0
Connected to example.com:0
220 ProFTPD Server (example.com FTP Server) [2201:8e8:1800:621c::1]
AUTH TLS
234 AUTH TLS successful
SSL connection established using TLSv1.3 (TLS_AES_256_GCM_SHA384)
PBSZ 0
200 PBSZ 0 successful
PROT P
200 Protection set to Private
USER username
331 Password required for username
PASS xxxx
230 User username logged in
SYST
215 UNIX Type: L8
TYPE I
200 Type set to I
PWD
257 "/" is the current directory
Loading directory listing / from server (LC_TIME=en_GB.UTF-8)
EPSV
229 Entering Extended Passive Mode (|||30180|)
LIST -aL
Comment 3 Franz Holzinger 2022-06-08 19:03:38 CEST
When I switch the screen with ALT-TAB, then after a while gFTP is crashed.


[franz@franz-820 ~]$ free(): invalid pointer

[3]+  Aborted                 (core dumped) gftp
Comment 4 Lewis Smith 2022-06-26 08:20:58 CEST
Apologies for having left this so long; it went off my radar.

Our current issued gftp-2.0.19-23.mga8 seems very old, since we have now in Cauldron new version 2.9.1b. The obvious solution to try is for us to update to that.

Assigning to wally, who nurses this package.

Assignee: bugsquad => jani.valimaa
CC: lewyssmith => (none)