CVE-2007-2165

NameCVE-2007-2165
DescriptionThe Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
proftpd-dfsg (PTS)jessie, jessie (lts)1.3.5e+r1.3.5-2+deb8u8fixed
stretch (security)1.3.5e+r1.3.5b-4+deb9u2fixed
stretch (lts), stretch1.3.5e+r1.3.5b-4+deb9u3fixed
buster1.3.6-4+deb10u6fixed
buster (security), buster (lts)1.3.6-4+deb10u4fixed
bullseye1.3.7a+dfsg-12+deb11u2fixed
bullseye (security)1.3.7a+dfsg-12+deb11u3fixed
bookworm1.3.8+dfsg-4+deb12u3fixed
bookworm (security)1.3.8+dfsg-4+deb12u4fixed
sid, trixie1.3.8.c+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
proftpdsource(unstable)1.3.0-24low
proftpd-dfsgsourceetch1.3.0-19etch1
proftpd-dfsgsource(unstable)1.3.0-24low

Notes

[sarge] - proftpd <no-dsa> (Minor issue)
Minor issue Fixed in 4.0r4 point release

Search for package or bug name: Reporting problems