Opened 5 months ago
Closed 4 months ago
#23208 closed enhancement (fixed)
proftpd-1.3.9a
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New micro version.
Change History (4)
comment:1 by , 5 months ago
| Priority: | normal → high |
|---|
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
1.3.9a - Released 27-Apr-2026 -------------------------------- - Issue 1886 - SCP transfers fail for files with spaces in their names. - Issue 1898 - LDAPDefaultGID ignored since 1.3.9. - Bug 4512 - Compilation of mod_wrap2 fails when the --enable-wrapper-options configure option is used. - Issue 1904 - mod_sftp fails to parse authorized user/host public keys with CRLF line endings. - Issue 1896 - Uploads using MODE Z sometimes result in corrupted files or broken transfers. - Issue 1911 - Remove usage of the deprecated MySQL_OPT_RECONNECT option for newer MySQL versions. - Issue 340 - Update usage of MySQL API for SSL/TLS connections to server. - Issue 1959 - mod_sftp leaks file descriptor when reading SFTPHostKey file. - Issue 1964 - Large/slow SCP downloads could be unnecessarily truncated by TimeoutStalled. - Issue 1960 - Handling of CRLs in mod_tls is incorrect, leading to confusing errors. - Issue 1963 - Resumed SSL_SESSION management in mod_tls leads to memory growth, infinite loop using newer OpenSSL versions. - Issue 1984 - mod_quotatab_ldap interactions can lead to segfault due to stale pointer. - Issue 2003 - RNTO before authentication leads to out-of-order response codes. - Issue 2009 - MaxLoginAttemptsFromUser event never triggers in mod_ban for SFTP sessions. - Issue 2019 - Using toupper(3) on non-ASCII FTP command bytes may cause remote DoS. - Issue 2020 - Out-of-bounds single byte read when FTP command input buffer starts with LF. - Issue 2030 - FTP command LIST/NLST -B can cause buffer overflow when listing certain crafted filenames. - Issue 2043 - Memory exhaustion with mod_log_forensic when downloading very large files via SFTP. - Issue 2046 - Setting process groups during authentication crashes when using mod_radius and <IfGroup>. - Issue 2052 - SQL injection possible via mod_sql because of is_escaped_text() logic error (CVE-2026-42167).
Fixed at 5881ce7bd5. Leaving open for SA.
Note:
See TracTickets
for help on using tickets.

This contains a fix for an SQL Injection vulnerability. I suspect most users of BLFS aren't affected, but better to be safe with these since there is a demonstration of remote code execution. https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce
Rated as 8.1 High.