CVE-2007-2165
Summary
| CVE | CVE-2007-2165 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-22 19:19:00 UTC |
| Updated | 2017-07-29 01:31:00 UTC |
| Description | The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Proftpd Project | Proftpd | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| ProFTPD Auth API Multiple Authentication Modules Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 34602 | OSVDB | osvdb.org | |
| Bug 237533 – CVE-2007-2165: proftpd auth bypass vulnerability | CONFIRM | bugzilla.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - ProFTPD Auth API State Error May Let Remote Users Access the System in Certain Cases | SECTRACK | securitytracker.com | Vendor Advisory |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Fedora update for proftpd - Advisories - Secunia | SECUNIA | secunia.com | |
| Bug 2922 – Auth API allows one auth module to authenticate user data provided by a different auth module | CONFIRM | bugs.proftpd.org | Patch |
| Mandriva update for proftpd - Advisories - Secunia | SECUNIA | secunia.com | |
| ProFTPD AUTH Multiple Authentication Module Security Bypass Vulnerability | BID | www.securityfocus.com | |
| [SECURITY] Fedora 7 Update: proftpd-1.3.1-2.fc7 | FEDORA | www.redhat.com | |
| #419255 - proftpd allows logins with almost no password if configured with SQLAuthTypes Plaintext - Debian Bug report logs | MISC | bugs.debian.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.