Описание
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
It was found that the Python's httplib library (used by urllib, urllib2 and others) did not properly check HTTPConnection.putheader() function arguments. An attacker could use this flaw to inject additional headers in a Python application that allowed user provided header names or values.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | python | Will not fix | ||
Red Hat Enterprise Linux 6 | python | Fixed | RHSA-2016:1626 | 18.08.2016 |
Red Hat Enterprise Linux 7 | python | Fixed | RHSA-2016:1626 | 18.08.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | python27-python | Fixed | RHSA-2016:1628 | 18.08.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | python33-python | Fixed | RHSA-2016:1629 | 18.08.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-python34-python | Fixed | RHSA-2016:1630 | 18.08.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | python27-python | Fixed | RHSA-2016:1628 | 18.08.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | python33-python | Fixed | RHSA-2016:1629 | 18.08.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | rh-python34-python | Fixed | RHSA-2016:1630 | 18.08.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | python27-python | Fixed | RHSA-2016:1628 | 18.08.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
5 Medium
CVSS2
Связанные уязвимости
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
CRLF injection vulnerability in the HTTPConnection.putheader function ...
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
EPSS
5.3 Medium
CVSS3
5 Medium
CVSS2