[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-16056Date: (C)2019-09-09   (M)2024-04-17


An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score : 5.0
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: NONE
Integrity: NONE 
Availability: NONE 
  
Reference:
FEDORA-2019-0d3fcae639
FEDORA-2019-232f092db0
FEDORA-2019-2b1f72899a
FEDORA-2019-4954d8773c
FEDORA-2019-50772cf122
FEDORA-2019-57462fa10d
FEDORA-2019-5dc275c9f2
FEDORA-2019-74ba24605e
FEDORA-2019-758824a3ff
FEDORA-2019-7ec5bb5d22
FEDORA-2019-986622833f
FEDORA-2019-a268ba7b23
FEDORA-2019-aba3cca74a
FEDORA-2019-b06ec6159b
FEDORA-2019-d202cda4f8
N/A
RHSA-2019:3725
RHSA-2019:3948
USN-4151-1
USN-4151-2
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
https://lists.debian.org/debian-lts-announce/2019/09/msg00018.html
https://lists.debian.org/debian-lts-announce/2019/09/msg00019.html
https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html
https://bugs.python.org/issue34155
https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9
https://security.netapp.com/advisory/ntap-20190926-0005/
https://www.oracle.com/security-alerts/cpujul2020.html
openSUSE-SU-2019:2389
openSUSE-SU-2019:2393
openSUSE-SU-2019:2438
openSUSE-SU-2019:2453
openSUSE-SU-2020:0086

CPE    5
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:8.0
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
cpe:/a:python:python
...
OVAL    52
oval:org.secpod.oval:def:89003067
oval:org.secpod.oval:def:2105792
oval:org.secpod.oval:def:69509
oval:org.secpod.oval:def:66834
...

© SecPod Technologies