Security update for proftpd
SUSE Patch
security@suse.de
SUSE Security Team
openSUSE-SU-2016:1334-1
Final
1
1
2016-05-18T09:08:20Z
current
2016-05-18T09:08:20Z
2016-05-18T09:08:20Z
cve-database/bin/generate-cvrf.pl
2017-02-24T01:00:00Z
Security update for proftpd
This proftpd update to version 1.3.5b fixes the following issues:
Security issues fixed:
- CVE-2016-3125: Fixed selection of DH groups from TLSDHParamFile. (boo#970890)
Bugs fixed:
- update to 1.3.5b:
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.5b
* SSH RSA hostkeys smaller than 2048 bits now work properly.
* MLSD response lines are now properly CRLF terminated.
The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)
https://lists.opensuse.org/opensuse-updates/2016-05/msg00080.html
E-Mail link for openSUSE-SU-2016:1334-1
https://www.suse.com/support/security/rating/
SUSE Security Ratings
openSUSE Leap 42.1
proftpd-1.3.5b-4.1
proftpd-devel-1.3.5b-4.1
proftpd-doc-1.3.5b-4.1
proftpd-lang-1.3.5b-4.1
proftpd-ldap-1.3.5b-4.1
proftpd-mysql-1.3.5b-4.1
proftpd-pgsql-1.3.5b-4.1
proftpd-radius-1.3.5b-4.1
proftpd-sqlite-1.3.5b-4.1
proftpd-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-devel-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-doc-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-lang-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-ldap-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-mysql-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-pgsql-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-radius-1.3.5b-4.1 as a component of openSUSE Leap 42.1
proftpd-sqlite-1.3.5b-4.1 as a component of openSUSE Leap 42.1
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.
CVE-2016-3125
openSUSE Leap 42.1:proftpd-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-devel-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-doc-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-lang-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-ldap-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-mysql-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-pgsql-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-radius-1.3.5b-4.1
openSUSE Leap 42.1:proftpd-sqlite-1.3.5b-4.1
moderate
Please Install the update.
https://lists.opensuse.org/opensuse-updates/2016-05/msg00080.html
https://www.suse.com/security/cve/CVE-2016-3125.html
CVE-2016-3125
https://bugzilla.suse.com/970890
SUSE Bug 970890