[CLSA-2026:1786531862] alt-python27: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 10:51:21 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to ftpcp() as well; ftpcp() previously passed the raw attacker-controllable IPv4 address and port from the source server's PASV reply straight to target.sendport(), letting a malicious source server redirect the target server's data connection to an arbitrary host:port. ftpcp() now uses the source server's real peer address, honoring the existing trust_server_pasv_ipv4_address opt-out
Updated packages:
  • alt-python27-2.7.18-41.el7.x86_64.rpm
    sha:ce8c39fe06e75072866514031c29fe2b3be207365f988b665f2088eb8aaf1dcf
  • alt-python27-debug-2.7.18-41.el7.x86_64.rpm
    sha:8e5b1c12233a274fac5026a557f4cc0a0b1a6bd6cedc142d8c158764caa0877b
  • alt-python27-devel-2.7.18-41.el7.x86_64.rpm
    sha:d6b36f021d14d9c5919678670aacac56401063be11a38eac8d825726ba1158ff
  • alt-python27-libs-2.7.18-41.el7.x86_64.rpm
    sha:be805620d905f2f506bf91b13538c8e877dceff30666705f40315b0178020ccd
  • alt-python27-test-2.7.18-41.el7.x86_64.rpm
    sha:d96f48d676f3b2afc14c438225aa27fc33857b4428e8ac52e8065ad553357540
  • alt-python27-tkinter-2.7.18-41.el7.x86_64.rpm
    sha:d8f72f9c004eeac36cf3e8c471b1619dc7d666cd74404e1f0e16ca5b0471231d
  • alt-python27-tools-2.7.18-41.el7.x86_64.rpm
    sha:de4102e5721ac9ebace4fd1e9a50ac1cf5dccbaafb2d4aa0d4200c9d6e4af87b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.