[CLSA-2026:1786536752] alt-python27: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 12:12:45 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to ftpcp() as well; ftpcp() previously passed the raw attacker-controllable IPv4 address and port from the source server's PASV reply straight to target.sendport(), letting a malicious source server redirect the target server's data connection to an arbitrary host:port. ftpcp() now uses the source server's real peer address, honoring the existing trust_server_pasv_ipv4_address opt-out
Updated packages:
  • alt-python27-2.7.18-41.el8.x86_64.rpm
    sha:6368bf4c2de271cc8deb6278eb1408ded3896239ee1bb3855684da6a1b4fccd0
  • alt-python27-debug-2.7.18-41.el8.x86_64.rpm
    sha:61c6b904f0442096a4f55d32d7c4c53448ed5f8f76036d7a1378339bf30181b2
  • alt-python27-devel-2.7.18-41.el8.x86_64.rpm
    sha:b6665341c9cc53b551f38f113e67be3725b91c7c0aefc0c365547eaf65fbdb39
  • alt-python27-libs-2.7.18-41.el8.x86_64.rpm
    sha:dc61750fb3e0b30f94ca005685ebddafb974b29d137b38ca4305924d8fbcb8cd
  • alt-python27-test-2.7.18-41.el8.x86_64.rpm
    sha:a4b2d778d61d09fd61a5587327fef5e86c4f4b695def9671cc0aad0254d28bce
  • alt-python27-tkinter-2.7.18-41.el8.x86_64.rpm
    sha:11bd01e06ce6d46239b42b1270cf9cf0150a893d323d532615325aacd4c12200
  • alt-python27-tools-2.7.18-41.el8.x86_64.rpm
    sha:2bac2450b7454b06e38465121057770973ce8b31e374ef9935a44271d4f08485
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.