[CLSA-2026:1786531539] alt-python27: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 10:45:51 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to ftpcp() as well; ftpcp() previously passed the raw attacker-controllable IPv4 address and port from the source server's PASV reply straight to target.sendport(), letting a malicious source server redirect the target server's data connection to an arbitrary host:port. ftpcp() now uses the source server's real peer address, honoring the existing trust_server_pasv_ipv4_address opt-out
Updated packages:
  • alt-python27-2.7.18-41.el10.x86_64.rpm
    sha:d4db3b020c8c262c12c7a8cde9ec02598233049a3543b5361274303d08314b5a
  • alt-python27-debug-2.7.18-41.el10.x86_64.rpm
    sha:fd20a3aa149f170afc6a2d560b3898586063f64228ec6930bec172baf499630d
  • alt-python27-devel-2.7.18-41.el10.x86_64.rpm
    sha:64cde27201022d833ad84aa9ec121b5f35cf197670f1f748b1cb209419703c24
  • alt-python27-libs-2.7.18-41.el10.x86_64.rpm
    sha:056c8703f37ccfaf3ba6452a0be189f939fd3a843376b0d329dfc8b2a48bd009
  • alt-python27-test-2.7.18-41.el10.x86_64.rpm
    sha:1669ebef1cae7541c29b5365978b725b90dc58decb6700565365bb01d47ef2b8
  • alt-python27-tkinter-2.7.18-41.el10.x86_64.rpm
    sha:e5d1dd0c5f67628c04c44e073e6e962ff34534a1b6afd935b33cb68bce99a547
  • alt-python27-tools-2.7.18-41.el10.x86_64.rpm
    sha:dd3ad1653016d0f073178dc57d1096389afedbe52cf5de50d8e665c56dbc1998
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.