CVE-2007-2165

NameCVE-2007-2165
DescriptionThe Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
proftpd-dfsg (PTS)bullseye1.3.7a+dfsg-12+deb11u2fixed
bullseye (security)1.3.7a+dfsg-12+deb11u3fixed
bookworm1.3.8+dfsg-4+deb12u3fixed
bookworm (security)1.3.8+dfsg-4+deb12u4fixed
trixie1.3.8.b+dfsg-4fixed
sid1.3.8.c+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
proftpdsource(unstable)1.3.0-24low
proftpd-dfsgsourceetch1.3.0-19etch1
proftpd-dfsgsource(unstable)1.3.0-24low

Notes

[sarge] - proftpd <no-dsa> (Minor issue)
Minor issue Fixed in 4.0r4 point release

Search for package or bug name: Reporting problems