CVE-2016-3125

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
05/04/2016
Last modified:
12/04/2025

Description

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:proftpd:proftpd:*:a:*:*:*:*:*:* 1.3.5 (including)
cpe:2.3:a:proftpd:proftpd:1.3.6:rc1:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*