Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Mageia 9 ProFTPD Critical SQL Injection Remote Code Exec 2026-0200

mageia
Calendar Grey June 12, 2026
Dist Mageia Esm H88
Explore a critical security update for ProFTPD in Mageia to mitigate SQL injection risks and remote code execution.
Security update

Summary

Description: CVE-2026-42167 mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). CVE-2026-44331 a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When "UseReverseDNS on" is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect

References

- https://bugs.mageia.org/show_bug.cgi?id=35445

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BEM6GPOFEILUHBP4D2KWIUHVXL5546WE/

- https://www.cve.org/CVERecord?id=CVE-2026-42167

- https://www.cve.org/CVERecord?id=CVE-2026-44331

Resolution

SRPMS

- 9/core/proftpd-1.3.8c-1.2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Jun 2026 
URL: https://advisories.mageia.org/MGASA-2026-0200.html
Type: security
CVE: CVE-2026-42167, CVE-2026-44331

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here