Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-4189
HistoryDec 31, 2021 - 12:00 a.m.

CVE-2021-4189

2021-12-3100:00:00
ubuntu.com
ubuntu.com
29

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.002 Low

EPSS

Percentile

55.7%

A flaw was found in Python, specifically in the FTP (File Transfer
Protocol) client library in PASV (passive) mode. The issue is how the FTP
client trusts the host from the PASV response by default. This flaw allows
an attacker to set up a malicious FTP server that can trick FTP clients
into connecting back to a given IP address and port. This vulnerability
could lead to FTP client scanning ports, which otherwise would not have
been possible.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpython2.7< 2.7.17-1~18.04ubuntu1.7UNKNOWN
ubuntu20.04noarchpython2.7< 2.7.18-1~20.04.3+esm1UNKNOWN
ubuntu22.04noarchpython2.7< 2.7.18-13ubuntu1.1+esm2UNKNOWN
ubuntu14.04noarchpython2.7< 2.7.6-8ubuntu0.6+esm12UNKNOWN
ubuntu16.04noarchpython2.7< 2.7.12-1ubuntu0~16.04.18+esm1UNKNOWN
ubuntu14.04noarchpython3.4< 3.4.3-1ubuntu1~14.04.7+esm12UNKNOWN
ubuntu14.04noarchpython3.5< anyUNKNOWN
ubuntu16.04noarchpython3.5< 3.5.2-2ubuntu0~16.04.13+esm2UNKNOWN
ubuntu18.04noarchpython3.6< 3.6.9-1~18.04ubuntu1.7UNKNOWN
ubuntu18.04noarchpython3.7< anyUNKNOWN
Rows per page:
1-10 of 111

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.002 Low

EPSS

Percentile

55.7%