CVE Database
/

CVE-2019-9948

Back to search

CVE-2019-9948

Published: Mar 23, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.

VendorProductVersions

n/a

n/a

affected
n/a

References

107549
vdb-entry
x_refsource_BID
openSUSE-SU-2019:1273
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1580
vendor-advisory
x_refsource_SUSE
RHSA-2019:1700
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-9bfb4a3e4b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-60a1defcd1
vendor-advisory
x_refsource_FEDORA
RHSA-2019:2030
vendor-advisory
x_refsource_REDHAT
USN-4127-2
vendor-advisory
x_refsource_UBUNTU
USN-4127-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:3335
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3520
vendor-advisory
x_refsource_REDHAT
GLSA-202003-26
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now