The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Proftpd | Proftpd | * | 1.3.5 (including) |
Proftpd | Proftpd | 1.3.6-rc1 (including) | 1.3.6-rc1 (including) |
Proftpd-dfsg | Ubuntu | artful | * |
Proftpd-dfsg | Ubuntu | esm-apps/xenial | * |
Proftpd-dfsg | Ubuntu | precise | * |
Proftpd-dfsg | Ubuntu | trusty | * |
Proftpd-dfsg | Ubuntu | upstream | * |
Proftpd-dfsg | Ubuntu | wily | * |
Proftpd-dfsg | Ubuntu | xenial | * |
Proftpd-dfsg | Ubuntu | yakkety | * |
Proftpd-dfsg | Ubuntu | zesty | * |