High severity7.5NVD Advisory· Published Apr 5, 2016· Updated May 6, 2026
CVE-2016-3125
CVE-2016-3125
Description
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.
Affected products
5cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- lists.fedoraproject.org/pipermail/package-announce/2016-March/179109.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2016-March/179143.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2016-06/msg00045.htmlnvdThird Party Advisory
- bugs.proftpd.org/show_bug.cginvdIssue Tracking
- proftpd.org/docs/NEWS-1.3.5bnvdRelease Notes
- proftpd.org/docs/NEWS-1.3.6rc2nvdRelease Notes
- www.openwall.com/lists/oss-security/2016/03/11/14nvdMailing List
- www.openwall.com/lists/oss-security/2016/03/11/3nvdMailing List
- lists.fedoraproject.org/pipermail/package-announce/2016-March/179905.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-05/msg00080.htmlnvd
News mentions
0No linked articles in our index yet.