[CLSA-2022:1649348075] Fix CVE(s): CVE-2021-4189
Type:
security
Severity:
moderate
Release date:
2022-04-07 16:14:35 UTC
Description:
* SECURITY UPDATE: Expose sensitive information - debian/patches/CVE-2021-4189.patch: alters ftplib.FTP class behavior to not trust the IPv4 address sent from the remote server when setting up a passive data channel in resposne in Lib/ftplib.py, Lib/test/test_ftplib.py. - CVE-2021-4189
Updated packages:
  • idle-python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_all.deb
    sha:1bcb63715460573fa52ab8f7e2a7c9baeb21e3f7
  • libpython3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:150a8a6b1a611b9b6ff2bbe1fc0bdd0ad5118cf2
  • libpython3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:3c38079f5bdf213ff85f192316ea2cb16c902225
  • libpython3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:78b1837c2afb705e433019d2023580b961b3678d
  • libpython3.5-stdlib_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:a1277bd0c0434ac257460c8391151fdfb91e6dad
  • libpython3.5-testsuite_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_all.deb
    sha:e41681f7f89ff47ec1d0554ca3cd7e780fd4ebdb
  • python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:b4b3c0141d9823f884e264ef41ab92e9b8e479ef
  • python3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:96780a028a8277a98ca138e76fe161ee38a29b97
  • python3.5-doc_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_all.deb
    sha:b1dde38a289842b0868a84462634be436820666a
  • python3.5-examples_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_all.deb
    sha:19ef019275a84db55cb70522dde41ad53160a2b8
  • python3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:9be1dd51edac344ebe4e740bd35b490d65c155cf
  • python3.5-venv_3.5.2-2ubuntu0~16.04.13+tuxcare.els3_amd64.deb
    sha:91dc65ce66a261fce8a65009b2d0dbda014d4820
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.