|
|
Log in / Subscribe / Register

Mageia alert MGASA-2026-0200 (proftpd)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2026-0200: Updated proftpd packages fix security vulnerabilities
Date:  Sat, 13 Jun 2026 01:29:02 +0200
Message-ID:  <20260612232902.E5245A0007@duvel.mageia.org>
Archive-link:  Article

MGASA-2026-0200 - Updated proftpd packages fix security vulnerabilities Publication date: 12 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0200.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-42167, CVE-2026-44331 Description: CVE-2026-42167 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). CVE-2026-44331 a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect References: - https://bugs.mageia.org/show_bug.cgi?id=35445 - https://lists.fedoraproject.org/archives/list/package-ann... - https://www.cve.org/CVERecord?id=CVE-2026-42167 - https://www.cve.org/CVERecord?id=CVE-2026-44331 SRPMS: - 9/core/proftpd-1.3.8c-1.2.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds