PT-2010-1239 · Python · Pyftpdlib

Publicado

2010-10-19

·

Atualizado

2022-05-01

·

CVE-2007-6741

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions pyftpdlib versions prior to 0.2.0
Description The issue concerns the ftp PORT function in FTPServer.py, which does not properly restrict TCP connections to privileged ports under certain conditions. This could potentially allow remote authenticated users to conduct FTP bounce attacks by crafting specific FTP data. An example of such an attack is against a NAT server.
Recommendations For versions prior to 0.2.0, update to version 0.2.0 or later to resolve the issue.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6741
GHSA-8XGX-75QW-6268
PYSEC-2010-25

Produtos afetados

Pyftpdlib