{"id":"MGASA-2016-0128","summary":"Updated proftpd packages fix security vulnerability","details":"A bug with security implications was found in the mod_tls module in\nProFTPD before 1.3.5b. This module has a configuration option\nTLSDHParamFile to specify user-defined Diffie Hellman parameters. The\nsoftware would ignore the user-defined parameters and use Diffie Hellman\nkey exchanges with 1024 bits (CVE-2016-3125).\n\nThe proftpd package has been updated to version 1.3.5b, which fixes this\nissue and other bugs, including:\n- SSH RSA hostkeys smaller than 2048 bits now work properly.\n- MLSD response lines are now properly CRLF terminated.\n","modified":"2026-04-16T06:24:40.166300344Z","published":"2016-03-31T20:22:34Z","upstream":["CVE-2016-3125"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0128.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17960"},{"type":"WEB","url":"http://www.proftpd.org/docs/RELEASE_NOTES-1.3.5b"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2016-March/179143.html"}],"affected":[{"package":{"name":"proftpd","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/proftpd?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.5b-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0128.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}