CVE-2007-6738: High severity G.rodola Pyftpdlib vulnerability
pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6738?
CVE-2007-6738 is considered a moderate severity vulnerability as it can expose sensitive information about data connection counts.
How do I fix CVE-2007-6738?
To mitigate CVE-2007-6738, upgrade pyftpdlib to version 0.1.1 or later.
Which versions of pyftpdlib are affected by CVE-2007-6738?
CVE-2007-6738 affects all versions of pyftpdlib prior to 0.1.1.
What type of attack does CVE-2007-6738 facilitate?
CVE-2007-6738 facilitates remote attackers gaining insight into the server's data connection activity.
Is CVE-2007-6738 present in the latest releases of pyftpdlib?
No, the latest releases of pyftpdlib do not have CVE-2007-6738 as it has been patched in version 0.1.1 and above.