Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Python | Python | 2.7.0 (including) | 2.7.17 (excluding) |
Python | Python | 3.0.0 (including) | 3.4.10 (excluding) |
Python | Python | 3.5.0 (including) | 3.5.7 (excluding) |
Python | Python | 3.6.0 (including) | 3.6.9 (excluding) |
Python | Python | 3.7.0 (including) | 3.7.3 (excluding) |
Red Hat Enterprise Linux 6 | RedHat | python-0:2.6.6-68.el6_10 | * |
Red Hat Enterprise Linux 7 | RedHat | python-0:2.7.5-77.el7_6 | * |
Red Hat Enterprise Linux 7.4 Advanced Update Support | RedHat | python-0:2.7.5-59.el7_4 | * |
Red Hat Enterprise Linux 7.4 Telco Extended Update Support | RedHat | python-0:2.7.5-59.el7_4 | * |
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | RedHat | python-0:2.7.5-59.el7_4 | * |
Red Hat Enterprise Linux 7.5 Extended Update Support | RedHat | python-0:2.7.5-70.el7_5 | * |
Red Hat Enterprise Linux 8 | RedHat | python27:2.7-8000020190410132513.c0efe978 | * |
Red Hat Enterprise Linux 8 | RedHat | python3-0:3.6.8-2.el8_0 | * |
Red Hat Enterprise Linux 8 | RedHat | python3-0:3.6.8-2.el8_0 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-python36-python-0:3.6.3-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-python-0:2.7.13-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-python35-python-0:3.5.1-12.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-python36-python-0:3.6.3-7.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-python-0:2.7.13-6.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-python35-python-0:3.5.1-12.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-python36-python-0:3.6.3-7.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | python27-python-0:2.7.13-6.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-python35-python-0:3.5.1-12.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-python36-python-0:3.6.3-7.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | python27-python-0:2.7.13-6.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-python35-python-0:3.5.1-12.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | RedHat | rh-python36-python-0:3.6.3-7.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | RedHat | python27-python-0:2.7.13-6.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | RedHat | rh-python35-python-0:3.5.1-12.el7 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | redhat-release-virtualization-host-0:4.2-8.4.el7 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | redhat-virtualization-host-0:4.2-20190411.1.el7_6 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | rhvm-appliance-0:4.2-20190411.1.el7 | * |
Python2.7 | Ubuntu | bionic | * |
Python2.7 | Ubuntu | cosmic | * |
Python2.7 | Ubuntu | trusty | * |
Python2.7 | Ubuntu | trusty/esm | * |
Python2.7 | Ubuntu | upstream | * |
Python2.7 | Ubuntu | xenial | * |
Python3.4 | Ubuntu | trusty | * |
Python3.4 | Ubuntu | trusty/esm | * |
Python3.5 | Ubuntu | trusty | * |
Python3.5 | Ubuntu | trusty/esm | * |
Python3.5 | Ubuntu | xenial | * |
Python3.6 | Ubuntu | bionic | * |
Python3.6 | Ubuntu | cosmic | * |
Python3.7 | Ubuntu | upstream | * |