CVE-2007-6737: High severity pyftpdlib vulnerability
Published Oct 19, 2010
·Updated
FTPServer.py in pyftpdlib before 0.2.0 does not increment the attemptedlogins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack.
Affected Software
3 affected componentsFixes available
pip/pyftpdlib<0.2.0
0.2.0
G.rodola Pyftpdlib=0.1
G.rodola Pyftpdlib<=0.1.1
Event History
Oct 19, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·06:45 PM
Frequently Asked Questions
1
What is the severity of CVE-2007-6737?
CVE-2007-6737 is classified as a high severity vulnerability due to its potential to facilitate brute-force attacks.
2
How do I fix CVE-2007-6737?
To fix CVE-2007-6737, upgrade to pyftpdlib version 0.2.0 or later.
3
What systems are affected by CVE-2007-6737?
CVE-2007-6737 affects pyftpdlib versions prior to 0.2.0, particularly version 0.1.
4
What type of vulnerability is CVE-2007-6737?
CVE-2007-6737 is a security vulnerability related to improper login attempts handling.
5
Can CVE-2007-6737 be exploited remotely?
Yes, CVE-2007-6737 can be exploited remotely by attackers using brute-force methods.