CVE-2016-3125: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.

Affected products

  • Fedoraproject Fedora: version 22 only; version 23 only
  • Opensuse Opensuse: version 13.1 only
  • ProFTPD ProFTPD: up to and including 1.3.5; version 1.3.6 only

Published 2016-04-05. Last modified 2026-06-17.