From: John M. <jw...@us...> - 2012-02-10 16:00:34
|
Update of /cvsroot/pdd/www.proftpd.org In directory vz-cvs-3.sog:/tmp/cvs-serv25793 Modified Files: index.epl Log Message: six months seems like a reasonable cutoff for news Index: index.epl =================================================================== RCS file: /cvsroot/pdd/www.proftpd.org/index.epl,v retrieving revision 1.120 retrieving revision 1.121 diff -u -d -r1.120 -r1.121 --- index.epl 11 Nov 2011 17:45:06 -0000 1.120 +++ index.epl 10 Feb 2012 16:00:30 -0000 1.121 @@ -34,165 +34,4 @@ release candidate of the 1.3.4 development cycle, containing multiple minor bugfixes and updates. The <a href="docs/RELEASE_NOTES-1.3.4rc3">RELEASE_NOTES</a> and <a href="docs/NEWS-1.3.4rc3">NEWS</a> files contain the full details.</p> -<h1>1.3.3e, 1.3.4rc2 released</h1> -[<i>01/Apr/2011</i>] -<p>The ProFTPD Project team is happy to release 1.3.3e to the community. -This is a maintenance release, containing backported fixes for bugs found -in the 1.3.3 release. The <a href="docs/RELEASE_NOTES-1.3.3e">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3e">NEWS</a> files contain the full details.</p> - -<p>We are also pleased to release 1.3.4rc2 to the community. This is the -second release candidate of the 1.3.4 development cycle, and contains -numerous new features, including the <code>mod_memcache</code> and -<code>mod_tls_memcache</code> modules, Memcache support, PCRE support, and -many <code>mod_sftp</code> bugfixes. The -<a href="docs/RELEASE_NOTES-1.3.4rc2">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.4rc2">NEWS</a> files contain the full details.</p> - -<h1>Update to the ProFTPD Compromise Report</h1> -[<i>16/Feb/2011</i>] -<p>By analyzing log files recovered from the compromised server, we can confirm -that the primary FTP site was compromised earlier than originally announced.</p> - -<p>In addition to the previously reported period from 2010-Nov-28 to 2010-Dec-02, -ftp.proftpd.org and the ProFTPD mirror network distributed files with malicious -content on 2010-Nov-16 between about 08:00 UTC and 13:00 UTC.</p> - -<p>In the weeks since, we've made several changes to restore and improve the -security of our software distribution sites. We've rebuilt the compromised -server from scratch, and implemented automated daily signature checks for -current releases on ftp.proftpd.org and all official mirrors.</p> - -<p>We'd like to thank everyone who offered and provided assistance, especially -those who reported suspicious files downloaded during the earlier time -window.</p> - -<h1>1.3.3d, 1.3.4rc1 released</h1> -[<i>17/Dec/2010</i>] -<p>The ProFTPD Project team is happy to release 1.3.3d to the community. -This is a maintenance release, containing backported fixes for bugs found -in the 1.3.3 release. The <a href="docs/RELEASE_NOTES-1.3.3d">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3d">NEWS</a> files contain the full details.</p> - -<p>We are also pleased to release 1.3.4rc1 to the community. This is the -first release candidate of the 1.3.4 development cycle, and contains -numerous new features, including the <code>mod_deflate</code>, -<code>mod_qos</code>, and <code>mod_ifversion</code> modules and -many <code>mod_sftp</code> bugfixes. The -<a href="docs/RELEASE_NOTES-1.3.4rc1">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.4rc1">NEWS</a> files contain the full details.</p> - -<h1>ftp.proftpd.org compromised</h1> -[<i>01/Dec/2010</i>] -<p>The ProFTPD Project team is sorry to announce that the Project's main FTP -server, as well as all of the mirror servers, have carried compromised -versions of the ProFTPD 1.3.3c source code, from the November 28 2010 to -December 2 2010. All users who run versions of ProFTPD which have been -downloaded and compiled in this time window are strongly advised to check their -systems for security compromises and install unmodified versions of ProFTPD. - -<p>To verify the integrity of your source files, use the PGP signatures which -can be found <a href="md5_pgp.html">here</a> as well as on the FTP servers. - -<p>The source code in <a href="cvs.html">CVS</a> was <b>not</b> affected. - -<h1>1.3.3c released</h1> -[<i>29/Oct/2010</i>] -<p>The ProFTPD Project team has released 1.3.3c to the community. -This is an <b>important security release</b>, containing fixes for a Telnet -IAC handling vulnerability and a directory traversal vulnerability in the -mod_site_misc module. The <a href="docs/RELEASE_NOTES-1.3.3c">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3c">NEWS</a> files contain the full details.</p> - -<h1>1.3.3b released</h1> -[<i>09/Sep/2010</i>] -<p>The ProFTPD Project team is happy to release 1.3.3b to the community. -This is a maintenance release, containing backported fixes for bugs found -in the 1.3.3 release. The <a href="docs/RELEASE_NOTES-1.3.3b">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3b">NEWS</a> files contain the full details.</p> - -<h1>1.3.3a released</h1> -[<i>01/Jul/2010</i>] -<p>The ProFTPD Project team is happy to release 1.3.3a to the community. -This is a maintenance release, containing backported fixes for bugs found -in the 1.3.3 release. The <a href="docs/RELEASE_NOTES-1.3.3a">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3a">NEWS</a> files contain the full details.</p> - -<h1>1.3.2e, 1.3.3 released</h1> -[<i>24/Feb/2010</i>] -<p>The ProFTPD Project team is pleased to release 1.3.2e to the community. -This is a maintenance release, containing fixes for bugs found in the 1.3.2 -in the 1.3.2 release. The <a href="docs/RELEASE_NOTES-1.3.2e">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.2e">NEWS</a> files contain the full details.</p> -Note that this will be the last maintenance release from the 1.3.2 branch. - -<p>We are also happy to release 1.3.3 to the community. This is the stable -release of the 1.3.3 branch, and contains minor additional fixes. The -<a href="docs/RELEASE_NOTES-1.3.3">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3">NEWS</a> files contain the full details.</p> - -<h1>1.3.2d, 1.3.3rc4 released</h1> -[<i>12/Feb/2010</i>] -<p>The ProFTPD Project team is pleased to release 1.3.2d to the community. -This is a maintenance release, containing fixes for bugs found in the 1.3.2 -in the 1.3.2 release. The <a href="docs/RELEASE_NOTES-1.3.2d">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.2d">NEWS</a> files contain the full details.</p> - -<p>We are also glad to release 1.3.3rc4 to the community. This is the -fourth release candidate of the 1.3.3 development cycle, and contains fixes -for mod_tls and mod_sftp build errors, memory leaks, and segfaults. The -<a href="docs/RELEASE_NOTES-1.3.3rc4">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3rc4">NEWS</a> files contain the full details.</p> - -<h1>1.3.2c, 1.3.3rc3 released</h1> -[<i>10/Dec/2009</i>] -<p>The ProFTPD Project team is happy to release 1.3.2c to the community. -This is a maintenance release, containing backported fixes for bugs found -in the 1.3.2 release. The <a href="docs/RELEASE_NOTES-1.3.2c">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.2c">NEWS</a> files contain the full details.</p> - -<p>We are also pleased to release 1.3.3rc3 to the community. This is the -third release candidate of the 1.3.3 development cycle, and contains -new SFTP features, a fix for the SSL/TLS renegotiation vulnerability -(CVE-2009-355), and an updated version of libtool. The -<a href="docs/RELEASE_NOTES-1.3.3rc3">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3rc3">NEWS</a> files contain the full details.</p> - -<h1>1.3.2b, 1.3.3rc2 released</h1> -[<i>20/Oct/2009</i>] -<p>The ProFTPD Project team is happy to release 1.3.2b to the community. -This is a maintenance release, containing backported fixes for bugs found -in the 1.3.2 release. The <a href="docs/RELEASE_NOTES-1.3.2b">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.2b">NEWS</a> files contain the full details.</p> - -<p>We are also pleased to release 1.3.3rc2 to the community. This is the -second release candidate of the 1.3.3 development cycle, and contains -numerous new features, including many SSH/SFTP fixes, a new -<code>mod_sql_passwd</code> module, support for "implicit" FTPS, and better -handling of lost database connections. As always, the -<a href="docs/RELEASE_NOTES-1.3.3rc2">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3rc2">NEWS</a> files contain the full details.</p> - -<h1>1.3.2a, 1.3.3rc1 released</h1> -[<i>30/Jun/2009</i>] -<p>The ProFTPD Project team is happy to release 1.3.2a to the community. -This is a maintenance release, containing backported fixes for bugs found -in the 1.3.2 release. The <a href="docs/RELEASE_NOTES-1.3.2a">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.2a">NEWS</a> files contain the full details.</p> - -<p>We are also pleased to release 1.3.3rc1 to the community. This is the -first release candidate of the 1.3.3 development cycle, and contains -numerous new features, including the <code>mod_exec</code>, -<code>mod_shaper</code>, and <code>mod_tls_shmcache</code> modules and -SSH2, SFTP, and SCP support (via the <code>mod_sftp</code> module). -The <a href="docs/RELEASE_NOTES-1.3.3rc1">RELEASE_NOTES</a> -and <a href="docs/NEWS-1.3.3rc1">NEWS</a> files contain the full details.</p> - -<h1>1.3.2 released</h1> -[<i>5/Feb/2009</i>] -<p>The ProFTPD Project team is happy to release 1.3.2 to the community. -This is a bugfix release, including a SQL injection vulnerability fix. -The <a href="docs/RELEASE_NOTES-1.3.2">RELEASE_NOTES</a> and -<a href="docs/NEWS-1.3.2">NEWS</a> files contain the full details.</p> - #include "footer.epl" |