PYSEC-2010-22

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pyftpdlib/PYSEC-2010-22.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2010-22
Aliases
Published
2010-10-19T20:00:00Z
Modified
2024-04-29T15:11:31.494422Z
Summary
[none]
Details

pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

References

Affected packages

PyPI / pyftpdlib

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/pyftpdlib/PYSEC-2010-22.yaml"