Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-16056

Опубликовано: 06 сент. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.

РелизСтатусПримечание
bionic

released

2.7.15-4ubuntu4~18.04.2
devel

DNE

disco

released

2.7.16-2ubuntu0.2
eoan

not-affected

2.7.17~rc1-1
esm-apps/focal

not-affected

2.7.17~rc1-1
esm-apps/jammy

not-affected

2.7.17~rc1-1
esm-infra-legacy/trusty

not-affected

2.7.6-8ubuntu0.6+esm3
esm-infra/bionic

not-affected

2.7.15-4ubuntu4~18.04.2
esm-infra/xenial

not-affected

2.7.12-1ubuntu0~16.04.9
focal

not-affected

2.7.17~rc1-1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

not-affected

3.4.3-1ubuntu1~14.04.7+esm4
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

not-affected

3.5.2-2ubuntu0~16.04.4~14.04.1+esm1
esm-infra/focal

DNE

esm-infra/xenial

not-affected

3.5.2-2ubuntu0~16.04.9
focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

РелизСтатусПримечание
bionic

released

3.6.8-1~18.04.3
devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

3.6.8-1~18.04.3
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

disco

released

3.7.3-2ubuntu0.2
eoan

not-affected

3.7.4-4
esm-apps/bionic

not-affected

3.7.5-2
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

EPSS

Процентиль: 69%
0.00625
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
почти 7 лет назад

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.

CVSS3: 7.5
nvd
почти 6 лет назад

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.

CVSS3: 7.5
debian
почти 6 лет назад

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3 ...

suse-cvrf
больше 4 лет назад

Security update for python

suse-cvrf
около 5 лет назад

Recommended update for python3

EPSS

Процентиль: 69%
0.00625
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Уязвимость CVE-2019-16056