9.8

CVE-2019-9636

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version >= 2.7.0 < 2.7.17
Python ≫ Python Version >= 3.0.0 < 3.4.10
Python ≫ Python Version >= 3.5.0 < 3.5.7
Python ≫ Python Version >= 3.6.0 < 3.6.9
Python ≫ Python Version >= 3.7.0 < 3.7.3
Fedoraproject ≫ Fedora Version 28
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 42.3
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Redhat ≫ Enterprise Linux Version 7.5
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Virtualization Version 4.0
   Redhat ≫ Enterprise Linux Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.81% 0.947
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CISA-ADP 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-173 Improper Handling of Alternate Encoding

The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.

http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
Third Party Advisory
Mailing List
https://www.oracle.com/security-alerts/cpujan2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4127-1/
Third Party Advisory
https://usn.ubuntu.com/4127-2/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/107400
Third Party Advisory
VDB Entry
https://bugs.python.org/issue36216
Patch
Vendor Advisory
Issue Tracking
https://github.com/python/cpython/pull/12201
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html
Third Party Advisory
Mailing List
https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html
Patch
Third Party Advisory
https://security.gentoo.org/glsa/202003-26
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190517-0001/
Third Party Advisory
https://access.redhat.com/errata/RHBA-2019:0763
Third Party Advisory
https://access.redhat.com/errata/RHBA-2019:0764
Third Party Advisory
https://access.redhat.com/errata/RHBA-2019:0959
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0710
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0765
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0806
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0902
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0981
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0997
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1467
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2980
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3170
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFBAAGM27H73OLYBUA2IAZFSUN6KGLME/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D3LXPABKVLFYUHRYJPM3CSS5MS6FXKS7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICBEGRHIPHWPG2VGYS6R4EVKVUUF4AQW/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFAXBEY2TGOBDRKTR556JBXBVFSAKD6I/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L25RTMKCF62DLC2XVSNXGX7C7HXISLVM/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TR6GCO3WTV4D5L23WTCBF275VE6BVNI3/