MGASA-2016-0128
Dashboard / Vulnerabilities / MGASA-2016-0128
Summary: Updated proftpd packages fix security vulnerability
Details: A bug with security implications was found in the mod_tls module in ProFTPD before 1.3.5b. This module has a configuration option TLSDHParamFile to specify user-defined Diffie Hellman parameters. The software would ignore the user-defined parameters and use Diffie Hellman key exchanges with 1024 bits (CVE-2016-3125). The proftpd package has been updated to version 1.3.5b, which fixes this issue and other bugs, including: - SSH RSA hostkeys smaller than 2048 bits now work properly. - MLSD response lines are now properly CRLF terminated.
References: https://advisories.mageia.org/MGASA-2016-0128.html, https://bugs.mageia.org/show_bug.cgi?id=17960, http://www.proftpd.org/docs/RELEASE_NOTES-1.3.5b, https://lists.fedoraproject.org/pipermail/package-announce/2016-March/179143.html
Affected packages
Package
Name: proftpd
Purl: pkg:rpm/mageia/proftpd?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
