Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4032

Опубликовано: 17 июн. 2024
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

A flaw was found in Python. The ipaddress module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. Due to this issue, it is possible that values will not be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10python3.12Not affected
Red Hat Enterprise Linux 6pythonOut of support scope
Red Hat Enterprise Linux 7pythonOut of support scope
Red Hat Enterprise Linux 7python3Out of support scope
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python39FixedRHSA-2024:596228.08.2024
Red Hat Enterprise Linux 8python39-develFixedRHSA-2024:596228.08.2024
Red Hat Enterprise Linux 8python3.12FixedRHSA-2024:696124.09.2024
Red Hat Enterprise Linux 8python3.11FixedRHSA-2024:696224.09.2024
Red Hat Enterprise Linux 8python3FixedRHSA-2024:697524.09.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-440
https://bugzilla.redhat.com/show_bug.cgi?id=2292921python: incorrect IPv4 and IPv6 private ranges

EPSS

Процентиль: 66%
0.00526
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

CVSS3: 7.5
nvd
около 1 года назад

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

CVSS3: 7.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
около 1 года назад

The \u201cipaddress\u201d module contained incorrect information about ...

suse-cvrf
10 месяцев назад

Security update for python3

EPSS

Процентиль: 66%
0.00526
Низкий

3.7 Low

CVSS3

Уязвимость CVE-2024-4032