[CLSA-2026:1786541588] alt-python27: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 13:33:22 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to ftpcp() as well; ftpcp() previously passed the raw attacker-controllable IPv4 address and port from the source server's PASV reply straight to target.sendport(), letting a malicious source server redirect the target server's data connection to an arbitrary host:port. ftpcp() now uses the source server's real peer address, honoring the existing trust_server_pasv_ipv4_address opt-out
Updated packages:
  • alt-python27-2.7.18-41.el9.x86_64.rpm
    sha:ff93e36e9b7e4f6f92ec027b75b9cc75695e69b4e1c63c06174ec848c1cb6a6c
  • alt-python27-debug-2.7.18-41.el9.x86_64.rpm
    sha:07ce4cae42a0b5429e30516214c5622852b6d2556f44ebdd3dd28917d62d5a4f
  • alt-python27-devel-2.7.18-41.el9.x86_64.rpm
    sha:b6209bb1e217cff878d126b16dcfd5020c1734059ffcc8f959af2600f0d83065
  • alt-python27-libs-2.7.18-41.el9.x86_64.rpm
    sha:bb501fb22387f50a288d118edfb65ee1872d1e8d127b73a62ede5f129e872200
  • alt-python27-test-2.7.18-41.el9.x86_64.rpm
    sha:b8c3608c43a44683212fa62def4c34dd13d080af0dcd0f4787e712205780a6b8
  • alt-python27-tkinter-2.7.18-41.el9.x86_64.rpm
    sha:a64276b558cb5f4314e5e68cc97c803a53f94641db7eff7dbc3e3cdfa5d40e73
  • alt-python27-tools-2.7.18-41.el9.x86_64.rpm
    sha:f056d059efc6413e15a24e2b5f974144c42601f3a7e6809fe419f1f71fd586ee
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.