GHSA-62xg-239j-vxg7

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-62xg-239j-vxg7/GHSA-62xg-239j-vxg7.json
Aliases
Published
2022-05-02T04:00:27Z
Modified
2022-09-21T03:41:31.296130Z
Details

Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the getpeername function having an ENOTCONN error, a different vulnerability than CVE-2010-3494.

References

Affected packages

PyPI / pyftpdlib

pyftpdlib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
0.5.2

Affected versions

0.*

0.2.0
0.3.0
0.4.0
0.5.0
0.5.1

Database specific

{
    "last_known_affected_version_range": "<= 0.5.1"
}