Wind River Support Network

HomeDefectsLIN7-10752
Fixed

LIN7-10752 : Security Advisory - python - CVE-2019-9947

Created: Mar 27, 2019    Updated: Jul 26, 2019
Resolved Date: Jul 26, 2019
Found In Version: unknown
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.2. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string or PATH_INFO) followed by an HTTP header or a Redis command. This is similar to CVE-2019-9740.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-9947 User=admin}

CVEs


Live chat
Online