Opened 5 months ago

Closed 4 months ago

#23208 closed enhancement (fixed)

proftpd-1.3.9a

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New micro version.

Change History (4)

comment:1 by Douglas R. Reno, 5 months ago

Priority: normal → high

This contains a fix for an SQL Injection vulnerability. I suspect most users of BLFS aren't affected, but better to be safe with these since there is a demonstration of remote code execution. ​https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce

1.3.9a
---------

  + Fix for SQL injection (CVE-2026-42167)

Rated as 8.1 High.

comment:2 by Joe Locash, 5 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 5 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
1.3.9a - Released 27-Apr-2026
--------------------------------
- Issue 1886 - SCP transfers fail for files with spaces in their names.
- Issue 1898 - LDAPDefaultGID ignored since 1.3.9.
- Bug 4512 - Compilation of mod_wrap2 fails when the --enable-wrapper-options
  configure option is used.
- Issue 1904 - mod_sftp fails to parse authorized user/host public keys with
  CRLF line endings.
- Issue 1896 - Uploads using MODE Z sometimes result in corrupted files or
  broken transfers.
- Issue 1911 - Remove usage of the deprecated MySQL_OPT_RECONNECT option for
  newer MySQL versions.
- Issue 340 - Update usage of MySQL API for SSL/TLS connections to server.
- Issue 1959 - mod_sftp leaks file descriptor when reading SFTPHostKey file.
- Issue 1964 - Large/slow SCP downloads could be unnecessarily truncated by
  TimeoutStalled.
- Issue 1960 - Handling of CRLs in mod_tls is incorrect, leading to confusing
  errors.
- Issue 1963 - Resumed SSL_SESSION management in mod_tls leads to memory
  growth, infinite loop using newer OpenSSL versions.
- Issue 1984 - mod_quotatab_ldap interactions can lead to segfault due to
  stale pointer.
- Issue 2003 - RNTO before authentication leads to out-of-order response codes.
- Issue 2009 - MaxLoginAttemptsFromUser event never triggers in mod_ban for
  SFTP sessions.
- Issue 2019 - Using toupper(3) on non-ASCII FTP command bytes may cause
  remote DoS.
- Issue 2020 - Out-of-bounds single byte read when FTP command input buffer
  starts with LF.
- Issue 2030 - FTP command LIST/NLST -B can cause buffer overflow when listing
  certain crafted filenames.
- Issue 2043 - Memory exhaustion with mod_log_forensic when downloading very
  large files via SFTP.
- Issue 2046 - Setting process groups during authentication crashes when using
  mod_radius and <IfGroup>.
- Issue 2052 - SQL injection possible via mod_sql because of is_escaped_text()
  logic error (CVE-2026-42167).

Fixed at 5881ce7bd5. Leaving open for SA.

comment:4 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-075 issued

Note: See TracTickets for help on using tickets.