Wind River Support Network

HomeDefectsLIN5-21933
Fixed

LIN5-21933 : Security Advisory - python - CVE-2016-5699

Created: Sep 11, 2016    Updated: May 29, 2018
Resolved Date: Sep 13, 2016
Found In Version: 5.0.1.37
Fix Version: 5.0.1.38
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5699

Other Downloads


Live chat
Online