CVE-2007-6738

pyftpdlib < 0.1.1 - Information Disclosure via PASV Command Port Prediction

Title source: llm
STIX 2.1

Description

pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

References (1)

Core 1
Core References

Scores

EPSS 0.0113
EPSS Percentile 63.0%

Details

Status published
Products (2)
g.rodola/pyftpdlib < 0.1
pypi/pyftpdlib 0 - 0.1.1PyPI
Published Oct 19, 2010
Tracked Since Feb 18, 2026