CVE-2021-40491

NameCVE-2021-40491
DescriptionThe ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs993476

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
inetutils (PTS)stretch2:1.9.4-2vulnerable
stretch (security)2:1.9.4-2+deb9u1vulnerable
buster2:1.9.4-7+deb10u1vulnerable
bullseye2:2.0-1vulnerable
bookworm, sid2:2.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
inetutilssource(unstable)2:2.2-1993476

Notes

[bullseye] - inetutils <no-dsa> (Minor issue)
[buster] - inetutils <no-dsa> (Minor issue)
[stretch] - inetutils <no-dsa> (Minor issue)
https://lists.gnu.org/archive/html/bug-inetutils/2021-06/msg00002.html
https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=58cb043b190fd04effdaea7c9403416b436e50dd

Search for package or bug name: Reporting problems