CVE-2007-2165
Summary
| CVE | CVE-2007-2165 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-22 19:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd. |
Risk And Classification
Primary CVSS: v2.0 5.1 from [email protected]
AV:N/AC:H/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Proftpd Project | Proftpd | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ProFTPD AUTH Multiple Authentication Module Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| #419255 - proftpd allows logins with almost no password if configured with SQLAuthTypes Plaintext - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Vendor Advisory |
| Bug 237533 – CVE-2007-2165: proftpd auth bypass vulnerability | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Bug 2922 – Auth API allows one auth module to authenticate user data provided by a different auth module | af854a3a-2127-422b-91ae-364da2661108 | bugs.proftpd.org | Patch |
| Fedora update for proftpd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mandriva update for proftpd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [SECURITY] Fedora 7 Update: proftpd-1.3.1-2.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - ProFTPD Auth API State Error May Let Remote Users Access the System in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Vendor Advisory |
| osvdb.org/34602 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| ProFTPD Auth API Multiple Authentication Modules Security Issue - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.