CVE-2021-40491: Medium severity GNU InetUtils vulnerability
Published Sep 1, 2021
·Updated
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
Affected Software
3 affected components
debian/inetutils<=2:2.0-1, <=2:1.9.4-7, <=2:1.9.4-7+deb10u1
GNU InetUtils<2.2
Debian Debian Linux=10.0
Remediation
Event History
Sep 3, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-40491?
CVE-2021-40491 is a vulnerability in the ftp client in GNU Inetutils before version 2.2.
2
How does CVE-2021-40491 affect GNU Inetutils?
CVE-2021-40491 affects GNU Inetutils versions up to and including 2.0-1, 1.9.4-7, and 1.9.4-7+deb10u1.
3
What is the severity of CVE-2021-40491?
CVE-2021-40491 has a severity score of 6.5 (medium).
4
How can I fix CVE-2021-40491?
There is currently no known fix for CVE-2021-40491. It is recommended to follow the provided references for any updates or patches.
5
Is there any additional information available for CVE-2021-40491?
Yes, you can find additional information about CVE-2021-40491 in the provided references.