PT-2016-1626 · Proftpd+1 · Proftpd+1
Hanno Böck
·
Published
2016-03-31
·
Updated
2024-06-15
·
CVE-2016-3125
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions prior to 1.3.5b
ProFTPD versions prior to 1.3.6rc2
Description
The issue exists due to improper handling of the
TLSDHParamFile directive in the mod tls module. This could lead to the use of a weaker than intended Diffie-Hellman (DH) key. As a result, attackers may be able to impact the integrity, availability, and confidentiality of information.Recommendations
For ProFTPD versions prior to 1.3.5b, update to version 1.3.5b or later.
For ProFTPD versions prior to 1.3.6rc2, update to version 1.3.6rc2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Proftpd