Уязвимость CVE-2019-16056: Информация

Описание

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.

Важность: HIGH (7,5) Вектор: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Опубликовано: 6 сентября 2019 г.
Изменено: 7 ноября 2023 г.

Исправленные пакеты

Имя пакета
Ветка
Исправлено в версии
Версия в репозитории
Errata ID
№ Задания
Состояние
pythonsisyphus2.7.17-alt12.7.18-alt11ALT-PU-2019-3103-1240064Исправлено
pythonp102.7.17-alt12.7.18-alt10ALT-PU-2019-3103-1240064Исправлено
pythonc10f12.7.17-alt12.7.18-alt10ALT-PU-2019-3103-1240064Исправлено
pythonc9f22.7.18-alt0.M90P.12.7.18-alt0.MC9.1ALT-PU-2020-3318-1261853Исправлено
pythonp112.7.17-alt12.7.18-alt11ALT-PU-2019-3103-1240064Исправлено
python3sisyphus3.8.1-alt13.12.2-alt1ALT-PU-2020-1434-1245000Исправлено
python3p103.8.1-alt13.9.18-alt1ALT-PU-2020-1434-1245000Исправлено
python3p93.7.11-alt13.7.17-alt1ALT-PU-2021-2653-1273501Исправлено
python3c10f13.8.1-alt13.9.18-alt0.c10f1.1ALT-PU-2020-1434-1245000Исправлено
python3c9f23.7.17-alt13.7.17-alt1ALT-PU-2024-3474-2342077Исправлено
python3p113.8.1-alt13.12.2-alt1ALT-PU-2020-1434-1245000Исправлено

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
https://bugs.python.org/issue34155
  • Issue Tracking
  • Vendor Advisory
https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9
  • Patch
[debian-lts-announce] 20190916 [SECURITY] [DLA 1925-1] python2.7 security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20190916 [SECURITY] [DLA 1924-1] python3.4 security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20200715 [SECURITY] [DLA 2280-1] python3.5 security update
  • Mailing List
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
  • Patch
  • Third Party Advisory
N/A
  • Patch
  • Third Party Advisory
openSUSE-SU-2020:0086
  • Third Party Advisory
RHSA-2019:3948
  • Third Party Advisory
openSUSE-SU-2019:2453
  • Third Party Advisory
RHSA-2019:3725
  • Third Party Advisory
openSUSE-SU-2019:2438
  • Third Party Advisory
openSUSE-SU-2019:2393
  • Third Party Advisory
openSUSE-SU-2019:2389
  • Third Party Advisory
USN-4151-2
  • Third Party Advisory
USN-4151-1
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190926-0005/
  • Third Party Advisory
[debian-lts-announce] 20200822 [SECURITY] [DLA 2337-1] python2.7 security update
  • Mailing List
  • Third Party Advisory
FEDORA-2019-4954d8773c
    FEDORA-2019-50772cf122
      FEDORA-2019-5dc275c9f2
        FEDORA-2019-2b1f72899a
          FEDORA-2019-232f092db0
            FEDORA-2019-986622833f
              FEDORA-2019-aba3cca74a
                FEDORA-2019-0d3fcae639
                  FEDORA-2019-74ba24605e
                    FEDORA-2019-b06ec6159b
                      FEDORA-2019-758824a3ff
                        FEDORA-2019-d202cda4f8
                          FEDORA-2019-57462fa10d
                            FEDORA-2019-7ec5bb5d22
                              FEDORA-2019-a268ba7b23
                                [bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image
                                    1. Конфигурация 1

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      End including
                                      2.7.16

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.5.0
                                      End including
                                      3.5.7

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.6.0
                                      End including
                                      3.6.9

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.7.0
                                      End including
                                      3.7.4

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.0.0
                                      End including
                                      3.0.1

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.1.0
                                      End including
                                      3.1.5

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.2.0
                                      End including
                                      3.2.6

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.3.0
                                      End including
                                      3.3.7

                                      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
                                      Start including
                                      3.4.0
                                      End including
                                      3.4.10

                                      Конфигурация 2

                                      cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

                                      cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

                                      cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

                                      Конфигурация 3

                                      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

                                      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

                                      Конфигурация 4

                                      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

                                      cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

                                      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

                                      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

                                      cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*

                                      Конфигурация 5

                                      cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*

                                      Конфигурация 6

                                      cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*

                                      cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*

                                      cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:*

                                      cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*

                                      cpe:2.3:a:oracle:communications_operations_monitor:*:*:*:*:*:*:*:*
                                      Start including
                                      4.1
                                      End including
                                      4.3

                                      cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*

                                      Конфигурация 7

                                      cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

                                      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*