CVE Database
/

CVE-2019-9947

Back to search

CVE-2019-9947

Published: Mar 23, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2019-1ffd6b6064
vendor-advisory
x_refsource_FEDORA
RHSA-2019:1260
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-ec26883852
vendor-advisory
x_refsource_FEDORA
RHSA-2019:2030
vendor-advisory
x_refsource_REDHAT
USN-4127-2
vendor-advisory
x_refsource_UBUNTU
USN-4127-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2019:2389
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2393
vendor-advisory
x_refsource_SUSE
RHSA-2019:3335
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3520
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3725
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0086
vendor-advisory
x_refsource_SUSE
GLSA-202003-26
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now