Bug 2036020 (CVE-2021-4189)
| Summary: | CVE-2021-4189 python: ftplib should not use the host from the PASV response | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | adev88, carl, caswilli, cstratak, dmalcolm, extras-orphan, fjansen, hhorak, jburrell, jeffrey.ness, jorton, jwong, kaycoth, lbalhar, m.cyprian, mhroncok, pviktori, python-maint, python-sig, rkuska, shcherbina.iryna, slavek.kabrda, thrnciar, TicoTimo |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | python 3.6.14, python 3.7.11, python 3.8.9, python 3.9.3, python 3.10.0 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-05-11 14:15:25 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2036021, 2036345, 2036346, 2036347, 2036349, 2036350, 2036351, 2036352, 2036353, 2036354, 2036355, 2064444, 2064445 | ||
| Bug Blocks: | 2034737, 2036048 | ||
|
Description
Dhananjay Arunesh
2021-12-29 10:28:46 UTC
Created python34 tracking bugs for this issue: Affects: epel-7 [bug 2036021] Upstream vulnerability page: https://python-security.readthedocs.io/vuln/ftplib-pasv.html Fixed upstream in 3.6.14, 3.7.11, 3.8.9, 3.9.3, and 3.10.0. Upstream fix: https://github.com/python/cpython/commit/0ab152c6b5d95caa2dc1a30fa96e10258b5f188e This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:1663 https://access.redhat.com/errata/RHSA-2022:1663 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1821 https://access.redhat.com/errata/RHSA-2022:1821 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1986 https://access.redhat.com/errata/RHSA-2022:1986 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-4189 |