ALAS2-2021-1670 --- python3ID: oval:org.secpod.oval:def:1700646 | Date: (C)2021-06-29 (M)2024-02-07 |
Class: PATCH | Family: unix |
A flaw was found in Python. The built-in modules httplib and http.client do not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation to the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity. In Python3"s Lib/test/multibytecodec_support.py CJK codec tests call eval on content retrieved via HTTP