PT-2010-1812 · Pyftpdlib · Pyftpdlib

Paolo Losi

·

Publicado

2010-10-19

·

Atualizado

2022-05-02

·

CVE-2009-5010

CVSS v4.0

6.3

Média

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pyftpdlib versions prior to 0.5.1
Description A race condition exists in the FTPHandler class in ftpserver.py, allowing remote attackers to cause a denial of service by establishing and then immediately closing a TCP connection. This leads to the accept function having an unexpected return value of None.
Recommendations For versions prior to 0.5.1, update to version 0.5.1 or later to resolve the issue.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-5010
GHSA-MPG6-RGP4-35RR
PYSEC-2010-7

Produtos afetados

Pyftpdlib