Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-0938

Опубликовано: 31 янв. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

The Python standard library functions urllib.parse.urlsplit and urlparse accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

РелизСтатусПримечание
devel

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

oracular

needs-triage

plucky

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

2.7.18-1~20.04.7+esm7
esm-apps/jammy

released

2.7.18-13ubuntu1.5+esm6
esm-infra-legacy/trusty

released

2.7.6-8ubuntu0.6+esm25
esm-infra/bionic

released

2.7.17-1~18.04ubuntu1.13+esm11
esm-infra/xenial

released

2.7.12-1ubuntu0~16.04.18+esm16
focal

ignored

end of standard support, was needed
jammy

needed

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

released

3.10.12-1~22.04.9
noble

DNE

oracular

DNE

plucky

DNE

upstream

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

released

3.11.0~rc1-1~22.04.1~esm3
esm-infra/focal

DNE

focal

DNE

jammy

needed

noble

DNE

oracular

DNE

plucky

DNE

upstream

released

3.11

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

released

3.12.3-1ubuntu0.5
oracular

released

3.12.7-1ubuntu2
plucky

DNE

upstream

released

3.12.9-1

Показывать по

РелизСтатусПримечание
devel

not-affected

3.13.2-1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

released

3.13.0-1ubuntu0.2
plucky

not-affected

3.13.2-1
upstream

released

3.13.2-1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

released

3.4.3-1ubuntu1~14.04.7+esm15
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

released

3.5.2-2ubuntu0~16.04.4~14.04.1+esm4
esm-infra/focal

DNE

esm-infra/xenial

released

3.5.2-2ubuntu0~16.04.13+esm16
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

released

3.6.9-1~18.04ubuntu1.13+esm4
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

released

3.7.5-2ubuntu1~18.04.2+esm5
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

released

3.8.0-3ubuntu1~18.04.2+esm4
esm-infra/focal

not-affected

3.8.10-0ubuntu1~20.04.16
focal

released

3.8.10-0ubuntu1~20.04.16
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

3.9.5-3ubuntu0~20.04.1+esm4
focal

ignored

end of standard support, was needed
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

released

3.9

Показывать по

EPSS

Процентиль: 76%
0.01039
Низкий

Связанные уязвимости

CVSS3: 6.8
redhat
5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

nvd
5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

msrc
3 месяца назад

Описание отсутствует

debian
5 месяцев назад

The Python standard library functions `urllib.parse.urlsplit` and `url ...

suse-cvrf
3 месяца назад

Security update for python

EPSS

Процентиль: 76%
0.01039
Низкий
Уязвимость CVE-2025-0938