Wind River Support Network

HomeDefectsLIN7-6788
Fixed

LIN7-6788 : Security Advisory - python - CVE-2016-5699

Created: Sep 11, 2016    Updated: Sep 8, 2018
Resolved Date: Sep 13, 2016
Found In Version: 7.0.0.19
Fix Version: 7.0.0.20
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5699 

Other Downloads


CVEs


Live chat
Online