mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
{ "binaries": [ { "binary_name": "proftpd-basic", "binary_version": "1.3.5e-1build1" }, { "binary_name": "proftpd-dev", "binary_version": "1.3.5e-1build1" }, { "binary_name": "proftpd-mod-geoip", "binary_version": "1.3.5e-1build1" }, { "binary_name": "proftpd-mod-ldap", "binary_version": "1.3.5e-1build1" }, { "binary_name": "proftpd-mod-mysql", "binary_version": "1.3.5e-1build1" }, { "binary_name": "proftpd-mod-odbc", "binary_version": "1.3.5e-1build1" }, { "binary_name": "proftpd-mod-pgsql", "binary_version": "1.3.5e-1build1" }, { "binary_name": "proftpd-mod-sqlite", "binary_version": "1.3.5e-1build1" } ] }
{ "binaries": [ { "binary_name": "proftpd-basic", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-dev", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-mod-geoip", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-mod-ldap", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-mod-mysql", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-mod-odbc", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-mod-pgsql", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-mod-snmp", "binary_version": "1.3.6c-2ubuntu0.1" }, { "binary_name": "proftpd-mod-sqlite", "binary_version": "1.3.6c-2ubuntu0.1" } ] }