First published: Wed Sep 01 2021(Updated: )
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/inetutils | <=2:2.0-1<=2:1.9.4-7<=2:1.9.4-7+deb10u1 | |
GNU inetutils | <2.2 | |
Debian Debian Linux | =10.0 |
https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=58cb043b190fd04effdaea7c9403416b436e50dd
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40491 is a vulnerability in the ftp client in GNU Inetutils before version 2.2.
CVE-2021-40491 affects GNU Inetutils versions up to and including 2.0-1, 1.9.4-7, and 1.9.4-7+deb10u1.
CVE-2021-40491 has a severity score of 6.5 (medium).
There is currently no known fix for CVE-2021-40491. It is recommended to follow the provided references for any updates or patches.
Yes, you can find additional information about CVE-2021-40491 in the provided references.