CVE-2021-46854

NameCVE-2021-46854
Descriptionmod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesELA-757-1
Debian Bugs993173

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
proftpd-dfsg (PTS)jessie, jessie (lts)1.3.5e+r1.3.5-2+deb8u8fixed
stretch (security)1.3.5e+r1.3.5b-4+deb9u2vulnerable
stretch (lts), stretch1.3.5e+r1.3.5b-4+deb9u3fixed
buster1.3.6-4+deb10u6fixed
buster (security), buster (lts)1.3.6-4+deb10u4vulnerable
bullseye1.3.7a+dfsg-12+deb11u2fixed
bookworm1.3.8+dfsg-4+deb12u3fixed
sid1.3.8.b+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
proftpd-dfsgsourcejessie1.3.5e+r1.3.5-2+deb8u8ELA-757-1
proftpd-dfsgsourcestretch1.3.5e+r1.3.5b-4+deb9u3ELA-757-1
proftpd-dfsgsourcebuster1.3.6-4+deb10u6
proftpd-dfsgsourcebullseye1.3.7a+dfsg-12+deb11u1
proftpd-dfsgsource(unstable)1.3.7c+dfsg-1993173

Notes

https://github.com/proftpd/proftpd/issues/1284
https://github.com/proftpd/proftpd/pull/1285
Fixed by: https://github.com/proftpd/proftpd/commit/10a227b4d50e0a2cd2faf87926f58d865da44e43 (v1.3.8rc2)
Fixed by: https://github.com/proftpd/proftpd/commit/e7c0b6e78a81fa97ec41ea6332e5e11b864089b8 (v1.3.7c)

Search for package or bug name: Reporting problems