The Auth API in ProFTPD before 20070417, when multiple simultaneous...
Vulnerability Description
The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2165
Credits & Attribution
No credits recorded in the NVD database.
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=419255
- http://bugs.proftpd.org/show_bug.cgi?id=2922
- https://bugzilla.redhat.com/show_bug.cgi?id=237533
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:130
- http://secunia.com/advisories/25724
- http://www.securityfocus.com/bid/23546
- http://secunia.com/advisories/24867
- http://osvdb.org/34602
- http://www.vupen.com/english/advisories/2007/1444
- http://securitytracker.com/id?1017931
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00065.html
- http://secunia.com/advisories/27516
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33733
More from proftpd project
View All →Affected Vendor
proftpd project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.