Release date:
2026-08-12 10:51:21 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
ftpcp() as well; ftpcp() previously passed the raw attacker-controllable
IPv4 address and port from the source server's PASV reply straight to
target.sendport(), letting a malicious source server redirect the target
server's data connection to an arbitrary host:port. ftpcp() now uses the
source server's real peer address, honoring the existing
trust_server_pasv_ipv4_address opt-out
Updated packages:
-
alt-python27-2.7.18-41.el7.x86_64.rpm
sha:ce8c39fe06e75072866514031c29fe2b3be207365f988b665f2088eb8aaf1dcf
-
alt-python27-debug-2.7.18-41.el7.x86_64.rpm
sha:8e5b1c12233a274fac5026a557f4cc0a0b1a6bd6cedc142d8c158764caa0877b
-
alt-python27-devel-2.7.18-41.el7.x86_64.rpm
sha:d6b36f021d14d9c5919678670aacac56401063be11a38eac8d825726ba1158ff
-
alt-python27-libs-2.7.18-41.el7.x86_64.rpm
sha:be805620d905f2f506bf91b13538c8e877dceff30666705f40315b0178020ccd
-
alt-python27-test-2.7.18-41.el7.x86_64.rpm
sha:d96f48d676f3b2afc14c438225aa27fc33857b4428e8ac52e8065ad553357540
-
alt-python27-tkinter-2.7.18-41.el7.x86_64.rpm
sha:d8f72f9c004eeac36cf3e8c471b1619dc7d666cd74404e1f0e16ca5b0471231d
-
alt-python27-tools-2.7.18-41.el7.x86_64.rpm
sha:de4102e5721ac9ebace4fd1e9a50ac1cf5dccbaafb2d4aa0d4200c9d6e4af87b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.