Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6923

Опубликовано: 01 авг. 2024
Источник: debian

Описание

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.13fixed3.13.0~rc2-1package
python3.12fixed3.12.5-1package
python3.11removedpackage
python3.11fixed3.11.2-6+deb12u5bookwormpackage
python3.9removedpackage
python2.7removedpackage
python2.7ignoredbullseyepackage
pypy3fixed7.3.18+dfsg-1package
pypy3no-dsabookwormpackage

Примечания

  • https://github.com/python/cpython/issues/121650

  • https://github.com/python/cpython/pull/122233

  • https://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0 (v3.13.0rc2)

  • https://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7 (v3.12.5)

  • https://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533 (v3.11.10)

  • https://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147 (v3.10.15)

  • https://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6 (v3.9.20)

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

CVSS3: 6.8
redhat
почти 2 года назад

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

CVSS3: 5.5
nvd
почти 2 года назад

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

CVSS3: 5.5
msrc
почти 2 года назад

Описание отсутствует

suse-cvrf
почти 2 года назад

Security update for python3