firefox: FTP PASV port-scanning
Package(s): | firefox seamonkey | CVE #(s): | CVE-2007-1562 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Created: | March 23, 2007 | Updated: | June 4, 2007 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description: | According to this advisory, the FTP protocol includes the PASV (passive) command which is used by Firefox to request an alternate data port. The specification of the FTP protocol allows the server response to include an alternate server address as well, although this is rarely used in practice. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Alerts: |
|
Posted Oct 28, 2007 14:28 UTC (Sun)
by kreutzm (guest, #4700)
[Link]
firefox: FTP PASV port-scanning
Version in Etch security is new enough (not vulnerable).