Wind River Support Network

HomeDefectsLIN6-11754
Fixed

LIN6-11754 : Security Advisory - python - CVE-2016-5699

Created: Sep 11, 2016    Updated: Dec 3, 2018
Resolved Date: Sep 13, 2016
Found In Version: 6.0.0.30
Fix Version: 6.0.0.31
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5699

Other Downloads


Live chat
Online