Candidate: CVE-2016-3125 PublicDate: 2016-04-05 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3125 http://bugs.proftpd.org/show_bug.cgi?id=4230 http://www.openwall.com/lists/oss-security/2016/03/11/14 http://proftpd.org/docs/RELEASE_NOTES-1.3.5b Description: The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_proftpd-dfsg: upstream_proftpd-dfsg: released (1.3.5b / 1.3.6rc2) precise_proftpd-dfsg: ignored (reached end-of-life) precise/esm_proftpd-dfsg: DNE (precise was needs-triage) trusty_proftpd-dfsg: ignored (reached end-of-life) trusty/esm_proftpd-dfsg: DNE (trusty was needed) vivid/stable-phone-overlay_proftpd-dfsg: DNE vivid/ubuntu-core_proftpd-dfsg: DNE wily_proftpd-dfsg: ignored (reached end-of-life) xenial_proftpd-dfsg: ignored (end of standard support, was needed) yakkety_proftpd-dfsg: ignored (reached end-of-life) zesty_proftpd-dfsg: ignored (reached end-of-life) artful_proftpd-dfsg: ignored (reached end-of-life) bionic_proftpd-dfsg: not-affected (1.3.5b-1) cosmic_proftpd-dfsg: not-affected (1.3.5b-1) disco_proftpd-dfsg: not-affected (1.3.5b-1) eoan_proftpd-dfsg: not-affected (1.3.5b-1) focal_proftpd-dfsg: not-affected (1.3.5b-1) groovy_proftpd-dfsg: not-affected (1.3.5b-1) hirsute_proftpd-dfsg: not-affected (1.3.5b-1) impish_proftpd-dfsg: not-affected (1.3.5b-1) jammy_proftpd-dfsg: not-affected (1.3.5b-1) devel_proftpd-dfsg: not-affected (1.3.5b-1)