CVE-2007-2165

NameCVE-2007-2165
DescriptionThe Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
proftpd-dfsg (PTS)buster1.3.6-4+deb10u6fixed
buster (security)1.3.6-4+deb10u4fixed
bullseye1.3.7a+dfsg-12+deb11u2fixed
bookworm1.3.8+dfsg-4+deb12u3fixed
sid, trixie1.3.8.b+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
proftpdsource(unstable)1.3.0-24low
proftpd-dfsgsourceetch1.3.0-19etch1
proftpd-dfsgsource(unstable)1.3.0-24low

Notes

[sarge] - proftpd <no-dsa> (Minor issue)
Minor issue Fixed in 4.0r4 point release

Search for package or bug name: Reporting problems