Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-29921

Опубликовано: 06 мая 2021
Источник: debian
EPSS Низкий

Описание

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.9fixed3.9.5-1experimentalpackage
python3.9fixed3.9.7-1package
python2.7not-affectedpackage
pypy3fixed7.3.8+dfsg-1package
pypy3no-dsabusterpackage
pypy3not-affectedbullseyepackage

Примечания

  • https://bugs.python.org/issue36384#msg392423

  • https://github.com/python/cpython/commit/60ce8f0be6354ad565393ab449d8de5d713f35bc (v3.10.0b1)

  • https://github.com/python/cpython/commit/5374fbc31446364bf5f12e5ab88c5493c35eaf04 (v3.9.5)

  • Introduced by: https://github.com/python/cpython/commit/e653d4d8e820a7a004ad399530af0135b45db27a (v3.8.0a4)

EPSS

Процентиль: 82%
0.01887
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.1
redhat
около 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
nvd
около 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

suse-cvrf
почти 4 года назад

Security update for python39

suse-cvrf
почти 4 года назад

Security update for python39

EPSS

Процентиль: 82%
0.01887
Низкий