The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Python | Python | 2.7.0 (including) | 2.7.13 (excluding) |
Python | Python | 3.3.0 (including) | 3.3.7 (excluding) |
Python | Python | 3.4.0 (including) | 3.4.6 (excluding) |
Python | Python | 3.5.0 (including) | 3.5.3 (excluding) |
Red Hat Enterprise Linux 6 | RedHat | python-0:2.6.6-66.el6_8 | * |
Red Hat Enterprise Linux 7 | RedHat | python-0:2.7.5-38.el7_2 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-python-0:2.7.8-18.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python33-python-0:3.3.2-18.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-python34-python-0:3.4.2-14.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python27-python-0:2.7.8-18.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python33-python-0:3.3.2-18.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | rh-python34-python-0:3.4.2-14.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | python27-python-0:2.7.8-18.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | python33-python-0:3.3.2-18.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-python34-python-0:3.4.2-14.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-python35-python-0:3.5.1-9.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-python-0:2.7.8-16.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python33-python-0:3.3.2-16.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-python34-python-0:3.4.2-13.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | rh-python35-python-0:3.5.1-9.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | python27-python-0:2.7.8-16.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | python33-python-0:3.3.2-16.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | rh-python34-python-0:3.4.2-13.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-python35-python-0:3.5.1-9.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | python27-python-0:2.7.8-16.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | python33-python-0:3.3.2-16.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-python34-python-0:3.4.2-13.el7 | * |
Python2.7 | Ubuntu | precise | * |
Python2.7 | Ubuntu | trusty | * |
Python2.7 | Ubuntu | upstream | * |
Python2.7 | Ubuntu | vivid/ubuntu-core | * |
Python2.7 | Ubuntu | wily | * |
Python2.7 | Ubuntu | xenial | * |
Python3.2 | Ubuntu | precise | * |
Python3.4 | Ubuntu | trusty | * |
Python3.4 | Ubuntu | upstream | * |
Python3.4 | Ubuntu | vivid/stable-phone-overlay | * |
Python3.4 | Ubuntu | vivid/ubuntu-core | * |
Python3.4 | Ubuntu | wily | * |
Python3.5 | Ubuntu | trusty | * |
Python3.5 | Ubuntu | upstream | * |
Python3.5 | Ubuntu | wily | * |
Python3.5 | Ubuntu | xenial | * |