EulerOS 2.0 SP13 : proftpd (EulerOS-SA-2026-2988)

high Nessus Plugin ID 332966

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the proftpd package installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a crafted domain name that is accessed in a reverse DNS lookup. When 'UseReverseDNS on' is enabled, the attacker-supplied hostname is passed unescaped into SQL queries. The character restrictions of DNS names may affect exploitability.(CVE-2026-44331)

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).(CVE-2026-42167)

Tenable has extracted the preceding description block directly from the EulerOS proftpd security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected proftpd packages.

See Also

http://www.nessus.org/u?803d3e11

Plugin Details

Severity: High

ID: 332966

File Name: EulerOS_SA-2026-2988.nasl

Version: 1.1

Type: Local

Published: 8/6/2026

Updated: 8/6/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.47

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-44331

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:proftpd

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 4/28/2026

Reference Information

CVE: CVE-2026-42167, CVE-2026-44331