Wind River Support Network

HomeDefectsLIN8-4676
Fixed

LIN8-4676 : Security Advisory - python - CVE-2016-5699

Created: Sep 11, 2016    Updated: Jan 21, 2020
Resolved Date: Sep 12, 2016
Found In Version: 8.0
Fix Version: 8.0.0.10
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5699

Other Downloads


CVEs


Live chat
Online