The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-updates/2016-06/msg00045.html | third party advisory vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179905.html | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/03/11/14 | mailing list |
http://proftpd.org/docs/NEWS-1.3.6rc2 | release notes |
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179109.html | third party advisory vendor advisory |
http://proftpd.org/docs/NEWS-1.3.5b | release notes |
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179143.html | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-updates/2016-05/msg00080.html | vendor advisory |
http://bugs.proftpd.org/show_bug.cgi?id=4230 | issue tracking |
http://www.openwall.com/lists/oss-security/2016/03/11/3 | mailing list |