CVE Vulnerabilities

CVE-2019-9636

Published: Mar 08, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
9.8 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

Affected Software

NameVendorStart VersionEnd Version
PythonPython2.7.0 (including)2.7.17 (excluding)
PythonPython3.0.0 (including)3.4.10 (excluding)
PythonPython3.5.0 (including)3.5.7 (excluding)
PythonPython3.6.0 (including)3.6.9 (excluding)
PythonPython3.7.0 (including)3.7.3 (excluding)
Red Hat Enterprise Linux 6RedHatpython-0:2.6.6-68.el6_10*
Red Hat Enterprise Linux 7RedHatpython-0:2.7.5-77.el7_6*
Red Hat Enterprise Linux 7.4 Advanced Update SupportRedHatpython-0:2.7.5-59.el7_4*
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportRedHatpython-0:2.7.5-59.el7_4*
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsRedHatpython-0:2.7.5-59.el7_4*
Red Hat Enterprise Linux 7.5 Extended Update SupportRedHatpython-0:2.7.5-70.el7_5*
Red Hat Enterprise Linux 8RedHatpython27:2.7-8000020190410132513.c0efe978*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-2.el8_0*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-2.el8_0*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-python36-python-0:3.6.3-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatpython27-python-0:2.7.13-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-python35-python-0:3.5.1-12.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python36-python-0:3.6.3-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatpython27-python-0:2.7.13-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python35-python-0:3.5.1-12.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatrh-python36-python-0:3.6.3-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatpython27-python-0:2.7.13-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatrh-python35-python-0:3.5.1-12.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatrh-python36-python-0:3.6.3-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatpython27-python-0:2.7.13-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatrh-python35-python-0:3.5.1-12.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-python36-python-0:3.6.3-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatpython27-python-0:2.7.13-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-python35-python-0:3.5.1-12.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatredhat-release-virtualization-host-0:4.2-8.4.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatredhat-virtualization-host-0:4.2-20190411.1.el7_6*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatrhvm-appliance-0:4.2-20190411.1.el7*
Python2.7Ubuntubionic*
Python2.7Ubuntucosmic*
Python2.7Ubuntuesm-infra-legacy/trusty*
Python2.7Ubuntuesm-infra/bionic*
Python2.7Ubuntuesm-infra/xenial*
Python2.7Ubuntutrusty*
Python2.7Ubuntutrusty/esm*
Python2.7Ubuntuupstream*
Python2.7Ubuntuxenial*
Python3.4Ubuntuesm-infra-legacy/trusty*
Python3.4Ubuntutrusty*
Python3.4Ubuntutrusty/esm*
Python3.5Ubuntuesm-infra-legacy/trusty*
Python3.5Ubuntuesm-infra/xenial*
Python3.5Ubuntutrusty*
Python3.5Ubuntutrusty/esm*
Python3.5Ubuntuxenial*
Python3.6Ubuntubionic*
Python3.6Ubuntucosmic*
Python3.6Ubuntuesm-infra/bionic*
Python3.7Ubuntuupstream*

References