Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:1334-1

Опубликовано: 18 мая 2016
Источник: suse-cvrf

Описание

Security update for proftpd

This proftpd update to version 1.3.5b fixes the following issues:

Security issues fixed:

  • CVE-2016-3125: Fixed selection of DH groups from TLSDHParamFile. (boo#970890)

Bugs fixed:

Список пакетов

openSUSE Leap 42.1
proftpd-1.3.5b-4.1
proftpd-devel-1.3.5b-4.1
proftpd-doc-1.3.5b-4.1
proftpd-lang-1.3.5b-4.1
proftpd-ldap-1.3.5b-4.1
proftpd-mysql-1.3.5b-4.1
proftpd-pgsql-1.3.5b-4.1
proftpd-radius-1.3.5b-4.1
proftpd-sqlite-1.3.5b-4.1

Описание

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.


Затронутые продукты
openSUSE Leap 42.1:proftpd-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-devel-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-doc-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-lang-1.3.5b-4.1

Ссылки