Bug 20296 - ftp is in active mode at startup, man page says it should be passive
Summary: ftp is in active mode at startup, man page says it should be passive
Status: RESOLVED WONTFIX
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 5
Hardware: x86_64 Linux
Priority: Normal minor
Target Milestone: ---
Assignee: Guillaume Rousse
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-02-15 13:46 CET by REINQUIN Franck
Modified: 2017-05-07 18:17 CEST (History)
0 users

See Also:
Source RPM: heimdal-ftp-1.5.3-6.mga5
CVE:
Status comment:


Attachments

Description REINQUIN Franck 2017-02-15 13:46:35 CET
Description of problem:
Man page and software are incoherent

Version-Release number of selected component (if applicable):
ftp --version
ftp (Heimdal 1.5.3)

How reproducible:
See below

Steps to Reproduce:
1.start ftp
2.type "passive"

This command toggles the current state and shows the new state.
It displays here : "Passive mode on.", which means that is was set to "active" at startup.

The man page reads : "-p    Use passive mode for data transfers. (...) This is the default now for all clients (ftp and pftp) due to security concerns using the PORT transfer mode. The flag is kept for compatibility only and has no effect anymore."

So the default mode at startup should be "passive".

Notes :
1. the source code (appl/ftp/ftp/main.c, line 105) does indeed set passivemode to 0 (inactive)
2. the man page provided in the source tree (appl/ftp/ftp/ftp.cat1) is different from the one packaged in the RPM. It does mention that the default setting is "active".

In conclusion, the man page included in the RPM is not compatible with the ftp tool it is shipped with.
David Walser 2017-02-16 01:45:09 CET

Assignee: bugsquad => guillomovitch

Comment 1 Guillaume Rousse 2017-05-07 18:17:34 CEST
Whereas perfectly true, this does not qualify as a security issue for an update in mageia 5. And the package in cauldron does not ship ftp binary anymore, fixing the issue.

Status: NEW => RESOLVED
Resolution: (none) => WONTFIX


Note You need to log in before you can comment on or make changes to this bug.