MEDIUM · 5.0

CVE-2007-6738

pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the nu...

Vulnerability Description

pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
G.RodolaPyftpdlib<= 0.1

References

FAQ

What is CVE-2007-6738?

CVE-2007-6738 is a vulnerability with a CVSS score of 5.0 (MEDIUM). pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the nu...

How severe is CVE-2007-6738?

CVE-2007-6738 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-6738?

Check the references section above for vendor advisories and patch information. Affected products include: G.Rodola Pyftpdlib.