CVE-2007-2165 Affecting proftpd-dfsg package, versions <1.3.0-24


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
52.98% (98th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-PROFTPDDFSG-1557414
  • published22 Apr 2007
  • disclosed22 Apr 2007

Introduced: 22 Apr 2007

CVE-2007-2165  (opens in a new tab)

How to fix?

Upgrade Debian:12 proftpd-dfsg to version 1.3.0-24 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream proftpd-dfsg package and not the proftpd-dfsg package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.

CVSS Scores

version 3.1