Release date:
2026-08-12 10:45:51 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
ftpcp() as well; ftpcp() previously passed the raw attacker-controllable
IPv4 address and port from the source server's PASV reply straight to
target.sendport(), letting a malicious source server redirect the target
server's data connection to an arbitrary host:port. ftpcp() now uses the
source server's real peer address, honoring the existing
trust_server_pasv_ipv4_address opt-out
Updated packages:
-
alt-python27-2.7.18-41.el10.x86_64.rpm
sha:d4db3b020c8c262c12c7a8cde9ec02598233049a3543b5361274303d08314b5a
-
alt-python27-debug-2.7.18-41.el10.x86_64.rpm
sha:fd20a3aa149f170afc6a2d560b3898586063f64228ec6930bec172baf499630d
-
alt-python27-devel-2.7.18-41.el10.x86_64.rpm
sha:64cde27201022d833ad84aa9ec121b5f35cf197670f1f748b1cb209419703c24
-
alt-python27-libs-2.7.18-41.el10.x86_64.rpm
sha:056c8703f37ccfaf3ba6452a0be189f939fd3a843376b0d329dfc8b2a48bd009
-
alt-python27-test-2.7.18-41.el10.x86_64.rpm
sha:1669ebef1cae7541c29b5365978b725b90dc58decb6700565365bb01d47ef2b8
-
alt-python27-tkinter-2.7.18-41.el10.x86_64.rpm
sha:e5d1dd0c5f67628c04c44e073e6e962ff34534a1b6afd935b33cb68bce99a547
-
alt-python27-tools-2.7.18-41.el10.x86_64.rpm
sha:dd3ad1653016d0f073178dc57d1096389afedbe52cf5de50d8e665c56dbc1998
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.