CVE-2021-40491
published 2021-09-03CVE-2021-40491: The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.00%
59.0th percentile
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | inetutils | < inetutils 2:2.2-1 (bookworm) | inetutils 2:2.2-1 (bookworm) |
| gnu | inetutils | < 2.2 | 2.2 |
| gnu | inetutils | >= 0 < 2:2.0-1+deb11u1 | 2:2.0-1+deb11u1 |
| gnu | inetutils | >= 0 < 2:2.2-1 | 2:2.2-1 |
| gnu | inetutils | >= 0 < 2:2.2-1 | 2:2.2-1 |
| gnu | inetutils | >= 0 < 2:2.2-1 | 2:2.2-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_debian3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qw8r-vcwc-vjc9: The ftp client in GNU Inetutils before 2
ghsa_unreviewed·2022-05-24·CVSS 3.7
CVE-2021-40491 [LOW] CWE-345 GHSA-qw8r-vcwc-vjc9: The ftp client in GNU Inetutils before 2
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
OSV
CVE-2021-40491: The ftp client in GNU Inetutils before 2
osv·2021-09-03·CVSS 3.7
CVE-2021-40491 [LOW] CVE-2021-40491: The ftp client in GNU Inetutils before 2
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
Ubuntu
Inetutils vulnerability
vendor_ubuntu·2022-08-08
CVE-2021-40491 Inetutils vulnerability
Title: Inetutils vulnerability
Summary: Inetutils could be made to crash if it received specially crafted
input.
It was discovered that Inetutils did not properly check the response of
ftp requests. A remote attacker could use this vulnerability to cause a crash
or run programs in the user machine.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-40491: inetutils - The ftp client in GNU Inetutils before 2.2 does not validate addresses returned ...
vendor_debian·2021·CVSS 3.7
CVE-2021-40491 [LOW] CVE-2021-40491: inetutils - The ftp client in GNU Inetutils before 2.2 does not validate addresses returned ...
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
Scope: local
bookworm: resolved (fixed in 2:2.2-1)
bullseye: resolved (fixed in 2:2.0-1+deb11u1)
forky: resolved (fixed in 2:2.2-1)
sid: resolved (fixed in 2:2.2-1)
trixie: resolved (fixed in 2:2.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993476https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=58cb043b190fd04effdaea7c9403416b436e50ddhttps://lists.debian.org/debian-lts-announce/2022/11/msg00033.htmlhttps://lists.gnu.org/archive/html/bug-inetutils/2021-06/msg00002.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993476https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=58cb043b190fd04effdaea7c9403416b436e50ddhttps://lists.debian.org/debian-lts-announce/2022/11/msg00033.htmlhttps://lists.gnu.org/archive/html/bug-inetutils/2021-06/msg00002.html
2021-09-03
Published