Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1000110

Опубликовано: 18 июл. 2016
Источник: redhat
CVSS3: 5
CVSS2: 5

Описание

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

It was discovered that the Python CGIHandler class did not properly protect against the HTTP_PROXY variable name clash in a CGI context. A remote attacker could possibly use this flaw to redirect HTTP requests performed by a Python CGI script to an attacker-controlled proxy via a malicious HTTP request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4pythonWill not fix
Red Hat Enterprise Linux 5pythonAffected
Red Hat Enterprise Linux 6pythonFixedRHSA-2016:162618.08.2016
Red Hat Enterprise Linux 7pythonFixedRHSA-2016:162618.08.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6python27-pythonFixedRHSA-2016:162818.08.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6python33-pythonFixedRHSA-2016:162918.08.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-python34-pythonFixedRHSA-2016:163018.08.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSpython27-pythonFixedRHSA-2016:162818.08.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSpython33-pythonFixedRHSA-2016:162918.08.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSrh-python34-pythonFixedRHSA-2016:163018.08.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1357334CGIHandler: sets environmental variable based on user supplied Proxy request header

5 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

CVSS3: 6.1
nvd
больше 5 лет назад

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

CVSS3: 6.1
debian
больше 5 лет назад

The CGIHandler class in Python before 2.7.12 does not protect against ...

CVSS3: 6.1
github
около 3 лет назад

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

suse-cvrf
почти 9 лет назад

Security update for python

5 Medium

CVSS3

5 Medium

CVSS2