Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-15367

Опубликовано: 20 янв. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

A flaw was found in the poplib module in the Python standard library. The poplib module does not reject control characters, such as newlines, in user-controlled input passed to POP3 commands. This issue allows an attacker to inject additional commands to be executed in the POP3 server.

Отчет

To exploit this issue, an attacker needs to have the privileges required to send malicious input to an application that sends POP3 commands to a server. Additionally, this flaw can allow attackers to manipulate the state of the mailbox (e.g., delete emails) and to potentially read metadata or specific email content, but it does not allow arbitrary code execution or OS command injection. Due to these reasons, this issue has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that no data passed to the poplib module contains newline or carriage return characters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10python3.14Affected
Red Hat Enterprise Linux 6pythonAffected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7pythonAffected
Red Hat Enterprise Linux 7python3Affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python39-devel:3.9/python39Not affected
Red Hat Enterprise Linux 9firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2431373cpython: POP3 command injection in user-controlled commands

EPSS

Процентиль: 23%
0.00077
Низкий

7.1 High

CVSS3

Связанные уязвимости

ubuntu
2 месяца назад

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

nvd
2 месяца назад

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

debian
2 месяца назад

The poplib module, when passed a user-controlled command, can have add ...

github
2 месяца назад

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

rocky
19 дней назад

Moderate: python3.11 security update

EPSS

Процентиль: 23%
0.00077
Низкий

7.1 High

CVSS3