Address Validation Flaw in GNU Inetutils FTP Client
CVE-2021-40491
6.5MEDIUM
What is CVE-2021-40491?
The FTP client in GNU Inetutils prior to version 2.2 lacks adequate validation of addresses provided by PASV/LSPV responses. This oversight can lead to scenarios where the returned addresses do not align with the server address, potentially allowing for man-in-the-middle attacks or other network-related exploits, similar to vulnerabilities noted in other software like curl.