CVE Database
/

CVE-2019-9636

Back to search

CVE-2019-9636

Published: Mar 8, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

VendorProductVersions

n/a

n/a

affected
n/a

References

107400
vdb-entry
x_refsource_BID
FEDORA-2019-243442e600
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-6e1938a3c5
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-6baeb15da3
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-cf725dd20b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-6b02154aa0
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-7d9f3cf3ce
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-51f1e08207
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-a122fe704d
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-86f32cbab1
vendor-advisory
x_refsource_FEDORA
RHSA-2019:0710
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0765
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0806
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2019:1273
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1282
vendor-advisory
x_refsource_SUSE
RHSA-2019:0902
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0981
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0997
vendor-advisory
x_refsource_REDHAT
RHBA-2019:0959
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2019:1371
vendor-advisory
x_refsource_SUSE
FEDORA-2019-1ffd6b6064
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-ec26883852
vendor-advisory
x_refsource_FEDORA
RHSA-2019:1467
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2019:1580
vendor-advisory
x_refsource_SUSE
RHBA-2019:0764
vendor-advisory
x_refsource_REDHAT
RHBA-2019:0763
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-7723d4774a
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-7df59302e0
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-9bfb4a3e4b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-60a1defcd1
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:1906
vendor-advisory
x_refsource_SUSE
USN-4127-2
vendor-advisory
x_refsource_UBUNTU
USN-4127-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2019-5dc275c9f2
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-2b1f72899a
vendor-advisory
x_refsource_FEDORA
RHSA-2019:2980
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3170
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-b06ec6159b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-d202cda4f8
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-57462fa10d
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2020:0086
vendor-advisory
x_refsource_SUSE
GLSA-202003-26
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now