PT-2010-1236 · None · Pyftpdlib

Published

2010-10-19

·

Updated

2022-05-01

·

CVE-2007-6738

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pyftpdlib versions prior to 0.1.1
Description The issue allows remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to the PASV command. This is because the software does not choose a random value for the port associated with the PASV command.
Recommendations For versions prior to 0.1.1, update to version 0.1.1 or later to resolve the issue.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6738
GHSA-GH7C-CG3X-PMCR
PYSEC-2010-22

Affected Products

Pyftpdlib