CVE Database
/

CVE-2019-18348

Back to search

CVE-2019-18348

Published: Oct 23, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2019-b06ec6159b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-d202cda4f8
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-57462fa10d
vendor-advisory
x_refsource_FEDORA
USN-4333-1
vendor-advisory
x_refsource_UBUNTU
USN-4333-2
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2020:0696
vendor-advisory
x_refsource_SUSE
FEDORA-2020-8bdd3fd7a4
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-ea5bdbcc90
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now