[PATCH] Ignore IP addresses in PASV responses by default, and add new option use_pasv_ip
authorYusuke Endoh <mame@ruby-lang.org>
Wed, 7 Jul 2021 03:05:44 +0000 (12:05 +0900)
committerUtkarsh Gupta <utkarsh@debian.org>
Sun, 19 Sep 2021 03:40:46 +0000 (04:40 +0100)
commit787cabd8da11ca988e01f61482c97dc9c3033385
tree3bac1eeb4d4fa350b184303c90b36deba15e2bb6
parent938cd7948241be1b0046804404af9997adf41b02
[PATCH] Ignore IP addresses in PASV responses by default, and add new option use_pasv_ip

This fixes CVE-2021-81810.
Reported by Alexandr Savca.

Re-adapted-By: Utkarsh Gupta <utkarsh@debian.org>
Gbp-Pq: Name CVE-2021-31810.patch
lib/net/ftp.rb
test/net/ftp/test_ftp.rb