CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
77.9%
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.
Vendor | Product | Version | CPE |
---|---|---|---|
proftpd | proftpd | * | cpe:2.3:a:proftpd:proftpd:*:a:*:*:*:*:*:* |
proftpd | proftpd | 1.3.6 | cpe:2.3:a:proftpd:proftpd:1.3.6:rc1:*:*:*:*:*:* |
opensuse | opensuse | 13.1 | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* |
fedoraproject | fedora | 22 | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* |
fedoraproject | fedora | 23 | cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:* |
bugs.proftpd.org/show_bug.cgi?id=4230
lists.fedoraproject.org/pipermail/package-announce/2016-March/179109.html
lists.fedoraproject.org/pipermail/package-announce/2016-March/179143.html
lists.fedoraproject.org/pipermail/package-announce/2016-March/179905.html
lists.opensuse.org/opensuse-updates/2016-05/msg00080.html
lists.opensuse.org/opensuse-updates/2016-06/msg00045.html
proftpd.org/docs/NEWS-1.3.5b
proftpd.org/docs/NEWS-1.3.6rc2
www.openwall.com/lists/oss-security/2016/03/11/14
www.openwall.com/lists/oss-security/2016/03/11/3
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
77.9%