Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2013-4359 (GCVE-0-2013-4359)
Vulnerability from cvelistv5
Published
2013-09-30 19:00
Modified
2024-08-06 16:38
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T16:38:02.185Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/" }, { "name": "[oss-security] 20130916 Re: CVE request: proftpd: mod_sftp/mod_sftp_pam invalid pool allocation during kbdint authentication", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2013/09/17/6" }, { "name": "DSA-2767", "tags": [ "vendor-advisory", "x_refsource_DEBIAN", "x_transferred" ], "url": "http://www.debian.org/security/2013/dsa-2767" }, { "name": "openSUSE-SU-2015:1031", "tags": [ "vendor-advisory", "x_refsource_SUSE", "x_transferred" ], "url": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html" }, { "name": "openSUSE-SU-2013:1563", "tags": [ "vendor-advisory", "x_refsource_SUSE", "x_transferred" ], "url": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://bugs.proftpd.org/show_bug.cgi?id=3973" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2013-09-11T00:00:00", "descriptions": [ { "lang": "en", "value": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2016-12-29T18:57:01", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/" }, { "name": "[oss-security] 20130916 Re: CVE request: proftpd: mod_sftp/mod_sftp_pam invalid pool allocation during kbdint authentication", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "http://www.openwall.com/lists/oss-security/2013/09/17/6" }, { "name": "DSA-2767", "tags": [ "vendor-advisory", "x_refsource_DEBIAN" ], "url": "http://www.debian.org/security/2013/dsa-2767" }, { "name": "openSUSE-SU-2015:1031", "tags": [ "vendor-advisory", "x_refsource_SUSE" ], "url": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html" }, { "name": "openSUSE-SU-2013:1563", "tags": [ "vendor-advisory", "x_refsource_SUSE" ], "url": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://bugs.proftpd.org/show_bug.cgi?id=3973" } ] } }, "cveMetadata": { "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2013-4359", "datePublished": "2013-09-30T19:00:00", "dateReserved": "2013-06-12T00:00:00", "dateUpdated": "2024-08-06T16:38:02.185Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2013-4359\",\"sourceIdentifier\":\"secalert@redhat.com\",\"published\":\"2013-09-30T21:55:07.347\",\"lastModified\":\"2025-04-11T00:51:21.963\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.\"},{\"lang\":\"es\",\"value\":\"Desbordamiento de entero en kbdint.c en mod_sftp en ProFTPD 1.3.4d y 1.3.5r3 permite a atacantes remotos causar denegaci\u00f3n de servicio (consumo de memoria) a trav\u00e9s de un valor grande del contador de respuestas en una petici\u00f3n de autenticaci\u00f3n, lo cual dispara una gran reserva de memoria.\"}],\"metrics\":{\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:L/Au:N/C:N/I:N/A:P\",\"baseScore\":5.0,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"PARTIAL\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":10.0,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-189\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:proftpd:proftpd:1.3.4:d:*:*:*:*:*:*\",\"matchCriteriaId\":\"D2542C4C-1D52-4DAB-80B9-30058AA1946B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:proftpd:proftpd:1.3.5:rc3:*:*:*:*:*:*\",\"matchCriteriaId\":\"E7B87E0F-D5C1-4B90-BFB7-9F59B17DA38A\"}]}]}],\"references\":[{\"url\":\"http://bugs.proftpd.org/show_bug.cgi?id=3973\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Patch\"]},{\"url\":\"http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Exploit\"]},{\"url\":\"http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://www.debian.org/security/2013/dsa-2767\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://www.openwall.com/lists/oss-security/2013/09/17/6\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Exploit\"]},{\"url\":\"http://bugs.proftpd.org/show_bug.cgi?id=3973\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\"]},{\"url\":\"http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\"]},{\"url\":\"http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www.debian.org/security/2013/dsa-2767\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www.openwall.com/lists/oss-security/2013/09/17/6\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\"]}]}}" } }
ghsa-ccxh-j5wp-7pr6
Vulnerability from github
Published
2022-05-17 03:13
Modified
2025-04-11 04:14
VLAI Severity ?
Details
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
{ "affected": [], "aliases": [ "CVE-2013-4359" ], "database_specific": { "cwe_ids": [], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2013-09-30T21:55:00Z", "severity": "MODERATE" }, "details": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.", "id": "GHSA-ccxh-j5wp-7pr6", "modified": "2025-04-11T04:14:17Z", "published": "2022-05-17T03:13:01Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-4359" }, { "type": "WEB", "url": "http://bugs.proftpd.org/show_bug.cgi?id=3973" }, { "type": "WEB", "url": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html" }, { "type": "WEB", "url": "http://www.debian.org/security/2013/dsa-2767" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2013/09/17/6" } ], "schema_version": "1.4.0", "severity": [] }
fkie_cve-2013-4359
Vulnerability from fkie_nvd
Published
2013-09-30 21:55
Modified
2025-04-11 00:51
Severity ?
Summary
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
References
▶ | URL | Tags | |
---|---|---|---|
secalert@redhat.com | http://bugs.proftpd.org/show_bug.cgi?id=3973 | Patch | |
secalert@redhat.com | http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/ | Exploit | |
secalert@redhat.com | http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html | ||
secalert@redhat.com | http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html | ||
secalert@redhat.com | http://www.debian.org/security/2013/dsa-2767 | ||
secalert@redhat.com | http://www.openwall.com/lists/oss-security/2013/09/17/6 | Exploit | |
af854a3a-2127-422b-91ae-364da2661108 | http://bugs.proftpd.org/show_bug.cgi?id=3973 | Patch | |
af854a3a-2127-422b-91ae-364da2661108 | http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/ | Exploit | |
af854a3a-2127-422b-91ae-364da2661108 | http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html | ||
af854a3a-2127-422b-91ae-364da2661108 | http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html | ||
af854a3a-2127-422b-91ae-364da2661108 | http://www.debian.org/security/2013/dsa-2767 | ||
af854a3a-2127-422b-91ae-364da2661108 | http://www.openwall.com/lists/oss-security/2013/09/17/6 | Exploit |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.4:d:*:*:*:*:*:*", "matchCriteriaId": "D2542C4C-1D52-4DAB-80B9-30058AA1946B", "vulnerable": true }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.5:rc3:*:*:*:*:*:*", "matchCriteriaId": "E7B87E0F-D5C1-4B90-BFB7-9F59B17DA38A", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation." }, { "lang": "es", "value": "Desbordamiento de entero en kbdint.c en mod_sftp en ProFTPD 1.3.4d y 1.3.5r3 permite a atacantes remotos causar denegaci\u00f3n de servicio (consumo de memoria) a trav\u00e9s de un valor grande del contador de respuestas en una petici\u00f3n de autenticaci\u00f3n, lo cual dispara una gran reserva de memoria." } ], "id": "CVE-2013-4359", "lastModified": "2025-04-11T00:51:21.963", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ] }, "published": "2013-09-30T21:55:07.347", "references": [ { "source": "secalert@redhat.com", "tags": [ "Patch" ], "url": "http://bugs.proftpd.org/show_bug.cgi?id=3973" }, { "source": "secalert@redhat.com", "tags": [ "Exploit" ], "url": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/" }, { "source": "secalert@redhat.com", "url": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html" }, { "source": "secalert@redhat.com", "url": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html" }, { "source": "secalert@redhat.com", "url": "http://www.debian.org/security/2013/dsa-2767" }, { "source": "secalert@redhat.com", "tags": [ "Exploit" ], "url": "http://www.openwall.com/lists/oss-security/2013/09/17/6" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch" ], "url": "http://bugs.proftpd.org/show_bug.cgi?id=3973" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit" ], "url": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.debian.org/security/2013/dsa-2767" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit" ], "url": "http://www.openwall.com/lists/oss-security/2013/09/17/6" } ], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-189" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
gsd-2013-4359
Vulnerability from gsd
Modified
2023-12-13 01:22
Details
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2013-4359", "description": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.", "id": "GSD-2013-4359", "references": [ "https://www.suse.com/security/cve/CVE-2013-4359.html", "https://www.debian.org/security/2013/dsa-2767", "https://advisories.mageia.org/CVE-2013-4359.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2013-4359" ], "details": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.", "id": "GSD-2013-4359", "modified": "2023-12-13T01:22:16.244295Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2013-4359", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_affected": "=", "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "http://bugs.proftpd.org/show_bug.cgi?id=3973", "refsource": "MISC", "url": "http://bugs.proftpd.org/show_bug.cgi?id=3973" }, { "name": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/", "refsource": "MISC", "url": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/" }, { "name": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html", "refsource": "MISC", "url": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html" }, { "name": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html", "refsource": "MISC", "url": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html" }, { "name": "http://www.debian.org/security/2013/dsa-2767", "refsource": "MISC", "url": "http://www.debian.org/security/2013/dsa-2767" }, { "name": "http://www.openwall.com/lists/oss-security/2013/09/17/6", "refsource": "MISC", "url": "http://www.openwall.com/lists/oss-security/2013/09/17/6" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:proftpd:proftpd:1.3.5:rc3:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:proftpd:proftpd:1.3.4:d:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2013-4359" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-189" } ] } ] }, "references": { "reference_data": [ { "name": "[oss-security] 20130916 Re: CVE request: proftpd: mod_sftp/mod_sftp_pam invalid pool allocation during kbdint authentication", "refsource": "MLIST", "tags": [ "Exploit" ], "url": "http://www.openwall.com/lists/oss-security/2013/09/17/6" }, { "name": "http://bugs.proftpd.org/show_bug.cgi?id=3973", "refsource": "CONFIRM", "tags": [ "Patch" ], "url": "http://bugs.proftpd.org/show_bug.cgi?id=3973" }, { "name": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/", "refsource": "MISC", "tags": [ "Exploit" ], "url": "http://kingcope.wordpress.com/2013/09/11/proftpd-mod_sftpmod_sftp_pam-invalid-pool-allocation-in-kbdint-authentication/" }, { "name": "openSUSE-SU-2013:1563", "refsource": "SUSE", "tags": [], "url": "http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html" }, { "name": "DSA-2767", "refsource": "DEBIAN", "tags": [], "url": "http://www.debian.org/security/2013/dsa-2767" }, { "name": "openSUSE-SU-2015:1031", "refsource": "SUSE", "tags": [], "url": "http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html" } ] } }, "impact": { "baseMetricV2": { "cvssV2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "MEDIUM", "userInteractionRequired": false } }, "lastModifiedDate": "2016-12-31T02:59Z", "publishedDate": "2013-09-30T21:55Z" } } }
opensuse-su-2024:10048-1
Vulnerability from csaf_opensuse
Published
2024-06-15 00:00
Modified
2024-06-15 00:00
Summary
proftpd-1.3.5b-2.5 on GA media
Notes
Title of the patch
proftpd-1.3.5b-2.5 on GA media
Description of the patch
These are all security issues fixed in the proftpd-1.3.5b-2.5 package on the GA media of openSUSE Tumbleweed.
Patchnames
openSUSE-Tumbleweed-2024-10048
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "proftpd-1.3.5b-2.5 on GA media", "title": "Title of the patch" }, { "category": "description", "text": "These are all security issues fixed in the proftpd-1.3.5b-2.5 package on the GA media of openSUSE Tumbleweed.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-Tumbleweed-2024-10048", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_10048-1.json" }, { "category": "self", "summary": "SUSE CVE CVE-2009-0542 page", "url": "https://www.suse.com/security/cve/CVE-2009-0542/" }, { "category": "self", "summary": "SUSE CVE CVE-2009-0543 page", "url": "https://www.suse.com/security/cve/CVE-2009-0543/" }, { "category": "self", "summary": "SUSE CVE CVE-2009-3639 page", "url": "https://www.suse.com/security/cve/CVE-2009-3639/" }, { "category": "self", "summary": "SUSE CVE CVE-2011-1137 page", "url": "https://www.suse.com/security/cve/CVE-2011-1137/" }, { "category": "self", "summary": "SUSE CVE CVE-2011-4130 page", "url": "https://www.suse.com/security/cve/CVE-2011-4130/" }, { "category": "self", "summary": "SUSE CVE CVE-2013-4359 page", "url": "https://www.suse.com/security/cve/CVE-2013-4359/" }, { "category": "self", "summary": "SUSE CVE CVE-2015-3306 page", "url": "https://www.suse.com/security/cve/CVE-2015-3306/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-3125 page", "url": "https://www.suse.com/security/cve/CVE-2016-3125/" } ], "title": "proftpd-1.3.5b-2.5 on GA media", "tracking": { "current_release_date": "2024-06-15T00:00:00Z", "generator": { "date": "2024-06-15T00:00:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2024:10048-1", "initial_release_date": "2024-06-15T00:00:00Z", "revision_history": [ { "date": "2024-06-15T00:00:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "proftpd-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-1.3.5b-2.5.aarch64", "product_id": "proftpd-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-devel-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-devel-1.3.5b-2.5.aarch64", "product_id": "proftpd-devel-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-doc-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-doc-1.3.5b-2.5.aarch64", "product_id": "proftpd-doc-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-lang-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-lang-1.3.5b-2.5.aarch64", "product_id": "proftpd-lang-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-ldap-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-ldap-1.3.5b-2.5.aarch64", "product_id": "proftpd-ldap-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-mysql-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-mysql-1.3.5b-2.5.aarch64", "product_id": "proftpd-mysql-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-pgsql-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-pgsql-1.3.5b-2.5.aarch64", "product_id": "proftpd-pgsql-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-radius-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-radius-1.3.5b-2.5.aarch64", "product_id": "proftpd-radius-1.3.5b-2.5.aarch64" } }, { "category": "product_version", "name": "proftpd-sqlite-1.3.5b-2.5.aarch64", "product": { "name": "proftpd-sqlite-1.3.5b-2.5.aarch64", "product_id": "proftpd-sqlite-1.3.5b-2.5.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "proftpd-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-1.3.5b-2.5.ppc64le", "product_id": "proftpd-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-devel-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-devel-1.3.5b-2.5.ppc64le", "product_id": "proftpd-devel-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-doc-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-doc-1.3.5b-2.5.ppc64le", "product_id": "proftpd-doc-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-lang-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-lang-1.3.5b-2.5.ppc64le", "product_id": "proftpd-lang-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-ldap-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-ldap-1.3.5b-2.5.ppc64le", "product_id": "proftpd-ldap-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-mysql-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-mysql-1.3.5b-2.5.ppc64le", "product_id": "proftpd-mysql-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-pgsql-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-pgsql-1.3.5b-2.5.ppc64le", "product_id": "proftpd-pgsql-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-radius-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-radius-1.3.5b-2.5.ppc64le", "product_id": "proftpd-radius-1.3.5b-2.5.ppc64le" } }, { "category": "product_version", "name": "proftpd-sqlite-1.3.5b-2.5.ppc64le", "product": { "name": "proftpd-sqlite-1.3.5b-2.5.ppc64le", "product_id": "proftpd-sqlite-1.3.5b-2.5.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "proftpd-1.3.5b-2.5.s390x", "product": { "name": "proftpd-1.3.5b-2.5.s390x", "product_id": "proftpd-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-devel-1.3.5b-2.5.s390x", "product": { "name": "proftpd-devel-1.3.5b-2.5.s390x", "product_id": "proftpd-devel-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-doc-1.3.5b-2.5.s390x", "product": { "name": "proftpd-doc-1.3.5b-2.5.s390x", "product_id": "proftpd-doc-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-lang-1.3.5b-2.5.s390x", "product": { "name": "proftpd-lang-1.3.5b-2.5.s390x", "product_id": "proftpd-lang-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-ldap-1.3.5b-2.5.s390x", "product": { "name": "proftpd-ldap-1.3.5b-2.5.s390x", "product_id": "proftpd-ldap-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-mysql-1.3.5b-2.5.s390x", "product": { "name": "proftpd-mysql-1.3.5b-2.5.s390x", "product_id": "proftpd-mysql-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-pgsql-1.3.5b-2.5.s390x", "product": { "name": "proftpd-pgsql-1.3.5b-2.5.s390x", "product_id": "proftpd-pgsql-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-radius-1.3.5b-2.5.s390x", "product": { "name": "proftpd-radius-1.3.5b-2.5.s390x", "product_id": "proftpd-radius-1.3.5b-2.5.s390x" } }, { "category": "product_version", "name": "proftpd-sqlite-1.3.5b-2.5.s390x", "product": { "name": "proftpd-sqlite-1.3.5b-2.5.s390x", "product_id": "proftpd-sqlite-1.3.5b-2.5.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "proftpd-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-1.3.5b-2.5.x86_64", "product_id": "proftpd-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-devel-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-devel-1.3.5b-2.5.x86_64", "product_id": "proftpd-devel-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-doc-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-doc-1.3.5b-2.5.x86_64", "product_id": "proftpd-doc-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-lang-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-lang-1.3.5b-2.5.x86_64", "product_id": "proftpd-lang-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-ldap-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-ldap-1.3.5b-2.5.x86_64", "product_id": "proftpd-ldap-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-mysql-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-mysql-1.3.5b-2.5.x86_64", "product_id": "proftpd-mysql-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-pgsql-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-pgsql-1.3.5b-2.5.x86_64", "product_id": "proftpd-pgsql-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-radius-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-radius-1.3.5b-2.5.x86_64", "product_id": "proftpd-radius-1.3.5b-2.5.x86_64" } }, { "category": "product_version", "name": "proftpd-sqlite-1.3.5b-2.5.x86_64", "product": { "name": "proftpd-sqlite-1.3.5b-2.5.x86_64", "product_id": "proftpd-sqlite-1.3.5b-2.5.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Tumbleweed", "product": { "name": "openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed", "product_identification_helper": { "cpe": "cpe:/o:opensuse:tumbleweed" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "proftpd-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-devel-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-devel-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-devel-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-devel-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-devel-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-devel-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-devel-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-devel-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-doc-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-doc-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-doc-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-doc-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-doc-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-doc-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-doc-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-doc-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-lang-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-lang-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-lang-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-lang-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-lang-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-lang-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-lang-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-lang-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-ldap-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-ldap-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-ldap-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-ldap-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-ldap-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-ldap-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-ldap-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-ldap-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-mysql-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-mysql-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-mysql-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-mysql-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-mysql-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-mysql-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-mysql-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-mysql-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-pgsql-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-pgsql-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-pgsql-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-pgsql-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-pgsql-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-pgsql-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-pgsql-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-pgsql-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-radius-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-radius-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-radius-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-radius-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-radius-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-radius-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-radius-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-radius-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-sqlite-1.3.5b-2.5.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64" }, "product_reference": "proftpd-sqlite-1.3.5b-2.5.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-sqlite-1.3.5b-2.5.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le" }, "product_reference": "proftpd-sqlite-1.3.5b-2.5.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-sqlite-1.3.5b-2.5.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x" }, "product_reference": "proftpd-sqlite-1.3.5b-2.5.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "proftpd-sqlite-1.3.5b-2.5.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" }, "product_reference": "proftpd-sqlite-1.3.5b-2.5.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" } ] }, "vulnerabilities": [ { "cve": "CVE-2009-0542", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2009-0542" } ], "notes": [ { "category": "general", "text": "SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a \"%\" (percent) character in the username, which introduces a \"\u0027\" (single quote) character during variable substitution by mod_sql.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2009-0542", "url": "https://www.suse.com/security/cve/CVE-2009-0542" }, { "category": "external", "summary": "SUSE Bug 475316 for CVE-2009-0542", "url": "https://bugzilla.suse.com/475316" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2009-0542" }, { "cve": "CVE-2009-0543", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2009-0543" } ], "notes": [ { "category": "general", "text": "ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2009-0543", "url": "https://www.suse.com/security/cve/CVE-2009-0543" }, { "category": "external", "summary": "SUSE Bug 475316 for CVE-2009-0543", "url": "https://bugzilla.suse.com/475316" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2009-0543" }, { "cve": "CVE-2009-3639", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2009-3639" } ], "notes": [ { "category": "general", "text": "The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a \u0027\\0\u0027 character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2009-3639", "url": "https://www.suse.com/security/cve/CVE-2009-3639" }, { "category": "external", "summary": "SUSE Bug 549740 for CVE-2009-3639", "url": "https://bugzilla.suse.com/549740" }, { "category": "external", "summary": "SUSE Bug 549741 for CVE-2009-3639", "url": "https://bugzilla.suse.com/549741" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2009-3639" }, { "cve": "CVE-2011-1137", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2011-1137" } ], "notes": [ { "category": "general", "text": "Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2011-1137", "url": "https://www.suse.com/security/cve/CVE-2011-1137" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2011-1137" }, { "cve": "CVE-2011-4130", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2011-4130" } ], "notes": [ { "category": "general", "text": "Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2011-4130", "url": "https://www.suse.com/security/cve/CVE-2011-4130" }, { "category": "external", "summary": "SUSE Bug 729830 for CVE-2011-4130", "url": "https://bugzilla.suse.com/729830" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2011-4130" }, { "cve": "CVE-2013-4359", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2013-4359" } ], "notes": [ { "category": "general", "text": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2013-4359", "url": "https://www.suse.com/security/cve/CVE-2013-4359" }, { "category": "external", "summary": "SUSE Bug 843444 for CVE-2013-4359", "url": "https://bugzilla.suse.com/843444" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2013-4359" }, { "cve": "CVE-2015-3306", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2015-3306" } ], "notes": [ { "category": "general", "text": "The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2015-3306", "url": "https://www.suse.com/security/cve/CVE-2015-3306" }, { "category": "external", "summary": "SUSE Bug 1142281 for CVE-2015-3306", "url": "https://bugzilla.suse.com/1142281" }, { "category": "external", "summary": "SUSE Bug 927290 for CVE-2015-3306", "url": "https://bugzilla.suse.com/927290" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2015-3306" }, { "cve": "CVE-2016-3125", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-3125" } ], "notes": [ { "category": "general", "text": "The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-3125", "url": "https://www.suse.com/security/cve/CVE-2016-3125" }, { "category": "external", "summary": "SUSE Bug 970890 for CVE-2016-3125", "url": "https://bugzilla.suse.com/970890" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-devel-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-doc-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-lang-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-ldap-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-mysql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-pgsql-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-radius-1.3.5b-2.5.x86_64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.aarch64", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.ppc64le", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.s390x", "openSUSE Tumbleweed:proftpd-sqlite-1.3.5b-2.5.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2016-3125" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…