[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1670 --- python3

ID: oval:org.secpod.oval:def:1700646Date: (C)2021-06-29   (M)2024-02-07
Class: PATCHFamily: unix




A flaw was found in Python. The built-in modules httplib and http.client do not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation to the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity. In Python3"s Lib/test/multibytecodec_support.py CJK codec tests call eval on content retrieved via HTTP

Platform:
Amazon Linux 2
Product:
python3
Reference:
ALAS2-2021-1670
CVE-2020-26116
CVE-2020-27619
CVE    2
CVE-2020-27619
CVE-2020-26116

© SecPod Technologies