CVE Database
/

CVE-2019-9740

Back to search

CVE-2019-9740

Published: Mar 13, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

VendorProductVersions

n/a

n/a

affected
n/a

References

107466
vdb-entry
x_refsource_BID
FEDORA-2019-1ffd6b6064
vendor-advisory
x_refsource_FEDORA
RHSA-2019:1260
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-ec26883852
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-7723d4774a
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-7df59302e0
vendor-advisory
x_refsource_FEDORA
RHSA-2019:2030
vendor-advisory
x_refsource_REDHAT
USN-4127-2
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2019:2131
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2133
vendor-advisory
x_refsource_SUSE
USN-4127-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:3335
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3520
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3725
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-b06ec6159b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-d202cda4f8
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-57462fa10d
vendor-advisory
x_refsource_FEDORA
GLSA-202003-26
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now