[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-20107Date: (C)2022-04-14   (M)2024-05-16


In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.6CVSS Score : 8.0
Exploit Score: 2.8Exploit Score: 8.0
Impact Score: 4.7Impact Score: 8.5
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: LOWAvailability: PARTIAL
Integrity: HIGH 
Availability: LOW 
  
Reference:
FEDORA-2022-0be85556b4
FEDORA-2022-1358cedf2d
FEDORA-2022-17a1bb7e78
FEDORA-2022-20e87fb0d1
FEDORA-2022-2e1d1205cf
FEDORA-2022-4a69d20cf4
FEDORA-2022-4b0dfda810
FEDORA-2022-4c788bdc40
FEDORA-2022-5ad25e3d3c
FEDORA-2022-5ea8aa7518
FEDORA-2022-79843dfb3c
FEDORA-2022-9cd41b6709
FEDORA-2022-9da5703d22
FEDORA-2022-9dd70781cb
FEDORA-2022-a8e50dc83e
FEDORA-2022-b499f2a9c6
FEDORA-2022-ce55d01569
FEDORA-2022-cece1d07d9
FEDORA-2022-d157a91e10
FEDORA-2022-d1682fef04
FEDORA-2022-dbe9a8f9ac
FEDORA-2022-ec74ac4079
GLSA-202305-02
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
https://bugs.python.org/issue24778
https://github.com/python/cpython/issues/68966
https://python-security.readthedocs.io/vuln/mailcap-shell-injection.html
https://security.netapp.com/advisory/ntap-20220616-0001/

CPE    1
cpe:/a:python:python
CWE    1
CWE-77
OVAL    63
oval:org.secpod.oval:def:707635
oval:org.secpod.oval:def:3300925
oval:org.secpod.oval:def:86364
oval:org.secpod.oval:def:3300921
...

© SecPod Technologies