Wind River Support Network

HomeDefectsLINCD-188
Fixed

LINCD-188 : Security Advisory - python - CVE-2019-18348

Created: Nov 13, 2019    Updated: May 13, 2022
Resolved Date: Feb 8, 2020
Found In Version: 10.20.3.0
Severity: Standard
Applicable for: Wind River Linux CD
Component/s: Userspace

Description

An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.)

CREATE(Triage):(User=admin) CVE-2019-18348 (https://nvd.nist.gov/vuln/detail/CVE-2019-18348)

CVEs


Live chat
Online