mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
- CVE-2026-42167:
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute
arbitrary code via a username, in scenarios where there is logging of
USER requests with an expansion such as %U, and the SQL backend allows
commands (e.g., COPY TO PROGRAM).
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-42167
- https://github.com/proftpd/proftpd/issues/2052
- af90843baf
The backport was provided by the Fedora Community:
- https://src.fedoraproject.org/rpms/proftpd/raw/epel9/f/2052.patch
(cherry picked from commit 0d5ce9ed84)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>