[PATCH] Ignore IP addresses in PASV responses by default, and add new option use_pasv_ip
authorYusuke Endoh <mame@ruby-lang.org>
Wed, 7 Jul 2021 03:05:44 +0000 (12:05 +0900)
committerUtkarsh Gupta <utkarsh@debian.org>
Sun, 5 Dec 2021 23:55:44 +0000 (23:55 +0000)
commit5a8fab7753d8cea75d0ccbf49069639a8805ac8e
treead40fae22b1abda06c2ba5aeaf9f6386dbae490a
parentbcbf2f7cf6eb63894bb09bd4b2fb3833e2f45b69
[PATCH] Ignore IP addresses in PASV responses by default, and add new option use_pasv_ip

This fixes CVE-2021-81810.
Reported by Alexandr Savca.

Re-adapted-By: Utkarsh Gupta <utkarsh@debian.org>
Gbp-Pq: Name CVE-2021-31810.patch
lib/net/ftp.rb
test/net/ftp/test_ftp.rb