Release date:
2026-08-12 12:12:45 UTC
Description:
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
ftpcp() as well; ftpcp() previously passed the raw attacker-controllable
IPv4 address and port from the source server's PASV reply straight to
target.sendport(), letting a malicious source server redirect the target
server's data connection to an arbitrary host:port. ftpcp() now uses the
source server's real peer address, honoring the existing
trust_server_pasv_ipv4_address opt-out
Updated packages:
-
alt-python27-2.7.18-41.el8.x86_64.rpm
sha:6368bf4c2de271cc8deb6278eb1408ded3896239ee1bb3855684da6a1b4fccd0
-
alt-python27-debug-2.7.18-41.el8.x86_64.rpm
sha:61c6b904f0442096a4f55d32d7c4c53448ed5f8f76036d7a1378339bf30181b2
-
alt-python27-devel-2.7.18-41.el8.x86_64.rpm
sha:b6665341c9cc53b551f38f113e67be3725b91c7c0aefc0c365547eaf65fbdb39
-
alt-python27-libs-2.7.18-41.el8.x86_64.rpm
sha:dc61750fb3e0b30f94ca005685ebddafb974b29d137b38ca4305924d8fbcb8cd
-
alt-python27-test-2.7.18-41.el8.x86_64.rpm
sha:a4b2d778d61d09fd61a5587327fef5e86c4f4b695def9671cc0aad0254d28bce
-
alt-python27-tkinter-2.7.18-41.el8.x86_64.rpm
sha:11bd01e06ce6d46239b42b1270cf9cf0150a893d323d532615325aacd4c12200
-
alt-python27-tools-2.7.18-41.el8.x86_64.rpm
sha:2bac2450b7454b06e38465121057770973ce8b31e374ef9935a44271d4f08485
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.