pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2010-10-19T19:00:00Z
Updated: 2024-09-16T22:09:55.962Z
Reserved: 2010-10-19T00:00:00Z
Link: CVE-2007-6738
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-10-19T20:00:01.923
Modified: 2024-11-21T00:40:53.463
Link: CVE-2007-6738
Redhat
No data.