Release date:
2026-08-12 13:33:22 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
ftpcp() as well; ftpcp() previously passed the raw attacker-controllable
IPv4 address and port from the source server's PASV reply straight to
target.sendport(), letting a malicious source server redirect the target
server's data connection to an arbitrary host:port. ftpcp() now uses the
source server's real peer address, honoring the existing
trust_server_pasv_ipv4_address opt-out
Updated packages:
-
alt-python27-2.7.18-41.el9.x86_64.rpm
sha:ff93e36e9b7e4f6f92ec027b75b9cc75695e69b4e1c63c06174ec848c1cb6a6c
-
alt-python27-debug-2.7.18-41.el9.x86_64.rpm
sha:07ce4cae42a0b5429e30516214c5622852b6d2556f44ebdd3dd28917d62d5a4f
-
alt-python27-devel-2.7.18-41.el9.x86_64.rpm
sha:b6209bb1e217cff878d126b16dcfd5020c1734059ffcc8f959af2600f0d83065
-
alt-python27-libs-2.7.18-41.el9.x86_64.rpm
sha:bb501fb22387f50a288d118edfb65ee1872d1e8d127b73a62ede5f129e872200
-
alt-python27-test-2.7.18-41.el9.x86_64.rpm
sha:b8c3608c43a44683212fa62def4c34dd13d080af0dcd0f4787e712205780a6b8
-
alt-python27-tkinter-2.7.18-41.el9.x86_64.rpm
sha:a64276b558cb5f4314e5e68cc97c803a53f94641db7eff7dbc3e3cdfa5d40e73
-
alt-python27-tools-2.7.18-41.el9.x86_64.rpm
sha:f056d059efc6413e15a24e2b5f974144c42601f3a7e6809fe419f1f71fd586ee
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.