CVE Vulnerabilities

CVE-2019-9636

Published: Mar 08, 2019 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
9.8 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

Affected Software

Name Vendor Start Version End Version
Python Python 2.7.0 (including) 2.7.17 (excluding)
Python Python 3.0.0 (including) 3.4.10 (excluding)
Python Python 3.5.0 (including) 3.5.7 (excluding)
Python Python 3.6.0 (including) 3.6.9 (excluding)
Python Python 3.7.0 (including) 3.7.3 (excluding)
Red Hat Enterprise Linux 6 RedHat python-0:2.6.6-68.el6_10 *
Red Hat Enterprise Linux 7 RedHat python-0:2.7.5-77.el7_6 *
Red Hat Enterprise Linux 7.4 Advanced Update Support RedHat python-0:2.7.5-59.el7_4 *
Red Hat Enterprise Linux 7.4 Telco Extended Update Support RedHat python-0:2.7.5-59.el7_4 *
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions RedHat python-0:2.7.5-59.el7_4 *
Red Hat Enterprise Linux 7.5 Extended Update Support RedHat python-0:2.7.5-70.el7_5 *
Red Hat Enterprise Linux 8 RedHat python27:2.7-8000020190410132513.c0efe978 *
Red Hat Enterprise Linux 8 RedHat python3-0:3.6.8-2.el8_0 *
Red Hat Enterprise Linux 8 RedHat python3-0:3.6.8-2.el8_0 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-python36-python-0:3.6.3-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat python27-python-0:2.7.13-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-python35-python-0:3.5.1-12.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python36-python-0:3.6.3-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat python27-python-0:2.7.13-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python35-python-0:3.5.1-12.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS RedHat rh-python36-python-0:3.6.3-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS RedHat python27-python-0:2.7.13-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS RedHat rh-python35-python-0:3.5.1-12.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS RedHat rh-python36-python-0:3.6.3-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS RedHat python27-python-0:2.7.13-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS RedHat rh-python35-python-0:3.5.1-12.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS RedHat rh-python36-python-0:3.6.3-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS RedHat python27-python-0:2.7.13-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS RedHat rh-python35-python-0:3.5.1-12.el7 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat redhat-release-virtualization-host-0:4.2-8.4.el7 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat redhat-virtualization-host-0:4.2-20190411.1.el7_6 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat rhvm-appliance-0:4.2-20190411.1.el7 *
Python2.7 Ubuntu bionic *
Python2.7 Ubuntu cosmic *
Python2.7 Ubuntu trusty *
Python2.7 Ubuntu trusty/esm *
Python2.7 Ubuntu upstream *
Python2.7 Ubuntu xenial *
Python3.4 Ubuntu trusty *
Python3.4 Ubuntu trusty/esm *
Python3.5 Ubuntu trusty *
Python3.5 Ubuntu trusty/esm *
Python3.5 Ubuntu xenial *
Python3.6 Ubuntu bionic *
Python3.6 Ubuntu cosmic *
Python3.7 Ubuntu upstream *

References