CVE-2021-40491

NameCVE-2021-40491
DescriptionThe ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3205-1, ELA-1057-1, ELA-746-1
Debian Bugs993476

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
inetutils (PTS)jessie, jessie (lts)2:1.9.2.39.3a460-3+deb8u2fixed
stretch (security)2:1.9.4-2+deb9u1vulnerable
stretch (lts), stretch2:1.9.4-2+deb9u2fixed
buster2:1.9.4-7+deb10u1vulnerable
buster (security)2:1.9.4-7+deb10u3fixed
bullseye2:2.0-1+deb11u2fixed
bookworm2:2.4-2+deb12u1fixed
sid, trixie2:2.5-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
inetutilssourcejessie2:1.9.2.39.3a460-3+deb8u2ELA-1057-1
inetutilssourcestretch2:1.9.4-2+deb9u2ELA-746-1
inetutilssourcebuster2:1.9.4-7+deb10u2DLA-3205-1
inetutilssourcebullseye2:2.0-1+deb11u1
inetutilssource(unstable)2:2.2-1993476

Notes

[stretch] - inetutils <no-dsa> (Minor issue)
https://lists.gnu.org/archive/html/bug-inetutils/2021-06/msg00002.html
https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=58cb043b190fd04effdaea7c9403416b436e50dd

Search for package or bug name: Reporting problems