Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-6741

Опубликовано: 19 окт. 2010
Источник: debian
EPSS Низкий

Описание

The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of the connection from the FTP client, which might allow remote authenticated users to conduct FTP bounce attacks via crafted FTP data, as demonstrated by an FTP bounce attack against a NAT server, a related issue to CVE-1999-0017.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pyftpdlibnot-affectedpackage

EPSS

Процентиль: 69%
0.00606
Низкий

Связанные уязвимости

nvd
около 15 лет назад

The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of the connection from the FTP client, which might allow remote authenticated users to conduct FTP bounce attacks via crafted FTP data, as demonstrated by an FTP bounce attack against a NAT server, a related issue to CVE-1999-0017.

CVSS3: 6.3
github
больше 3 лет назад

Improper privilege management in pyftpdlib

EPSS

Процентиль: 69%
0.00606
Низкий