Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-29921

Опубликовано: 06 мая 2021
Источник: debian

Описание

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.9fixed3.9.5-1experimentalpackage
python3.9fixed3.9.7-1package
python2.7not-affectedpackage
pypy3fixed7.3.8+dfsg-1package
pypy3no-dsabusterpackage
pypy3not-affectedbullseyepackage

Примечания

  • https://bugs.python.org/issue36384#msg392423

  • https://github.com/python/cpython/commit/60ce8f0be6354ad565393ab449d8de5d713f35bc (v3.10.0b1)

  • https://github.com/python/cpython/commit/5374fbc31446364bf5f12e5ab88c5493c35eaf04 (v3.9.5)

  • Introduced by: https://github.com/python/cpython/commit/e653d4d8e820a7a004ad399530af0135b45db27a (v3.8.0a4)

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.1
redhat
больше 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
nvd
больше 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

suse-cvrf
около 4 лет назад

Security update for python39

suse-cvrf
около 4 лет назад

Security update for python39