Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-2165
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2165

Description:
The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/33733

ST
  1017931

SAID
  Secunia Advisory: SA24867
  Secunia Advisory: SA25724
  Secunia Advisory: SA27516

MISC
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=419255

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2007:130

FEDORA

CONFIRM
  http://bugs.proftpd.org/show_bug.cgi?id=2922

BID
  23546


Return to the previous page.