[CLSA-2022:1649170553] Fix CVE(s): CVE-2021-4189
Type:
security
Severity:
moderate
Release date:
2022-04-05 14:55:53 UTC
Description:
* SECURITY UPDATE: Expose sensitive information - debian/patches/CVE-2021-4189.patch: alters ftplib.FTP class behavior to not trust the IPv4 address sent from the remote server when setting up a passive data channel in resposne in Lib/ftplib.py, Lib/test/test_ftplib.py. - CVE-2021-4189
Updated packages:
  • idle-python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_all.deb
    sha:8a26f64512f7638e7339f77d6d61c24c8675f8ad
  • libpython2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_amd64.deb
    sha:e3523f7a7f004c83a8f45f11ccb85b63687d1817
  • libpython2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_amd64.deb
    sha:e0bd47b4b303800ce6e2207c9ec8da2266c9034a
  • libpython2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_amd64.deb
    sha:50ee951394f02370562e3b4663aff2855325b133
  • libpython2.7-stdlib_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_amd64.deb
    sha:1a51bba3db6030a8d96f0a05c39fe5b2173888b3
  • libpython2.7-testsuite_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_all.deb
    sha:197aa569bb532cfbe793fa7a0b7dcbe685f03daa
  • python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_amd64.deb
    sha:c85837a31896a6556e9a2bac22b04265fd75b2ce
  • python2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_amd64.deb
    sha:50f9170d7f10b98ef1093babf1cb6e0225606229
  • python2.7-doc_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_all.deb
    sha:ecb4b9d75437ac6127e308a84646b68d81dbfc65
  • python2.7-examples_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_all.deb
    sha:10d81b6a288b08dcfd2e1580548c32427cd2c457
  • python2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els3_amd64.deb
    sha:eae76a2c20a28615fd7797d6b2f9ab5c10e5cef9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.