CVE-2019-9636

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during… (CVE-2019-9636)

criticalEPSS 8.8%

Description

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

Metrics

Severity
critical
no public PoC known
9.8
Source: nvd-v3
94.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
8.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-03-08 21:00 UTC

Affected operating systems

  • linux

    debian / debian_linux8.0

  • linux

    debian / debian_linux9.0

  • linux

    redhat / enterprise_linux7.5

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux_desktop6.0

  • linux

    redhat / enterprise_linux_eus7.5

  • linux

    redhat / enterprise_linux_eus8.1

  • linux

    redhat / enterprise_linux_eus8.2

  • linux

    redhat / enterprise_linux_eus8.4

  • linux

    redhat / enterprise_linux_eus8.6

  • linux

    redhat / enterprise_linux_server6.0

  • linux

    redhat / enterprise_linux_server_aus7.4

  • linux

    redhat / enterprise_linux_server_aus8.2

  • linux

    redhat / enterprise_linux_server_aus8.4

  • linux

    redhat / enterprise_linux_server_eus5.6

  • linux

    redhat / enterprise_linux_server_tus7.4

  • linux

    redhat / enterprise_linux_server_tus8.2

  • linux

    redhat / enterprise_linux_server_tus8.4

  • linux

    redhat / enterprise_linux_server_tus8.6

  • linux

    redhat / enterprise_linux_workstation6.0

  • linux

    opensuse / leap15.0

  • linux

    opensuse / leap15.1

  • linux

    opensuse / leap42.3

  • linux

    canonical / ubuntu_linux12.04

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • oracle

    sun_zfs_storage_appliance_kit

  • python

    python2.7.0 – 2.7.17

  • python

    python3.0.0 – 3.4.10

  • python

    python3.5.0 – 3.5.7

  • python

    python3.6.0 – 3.6.9

  • python

    python3.7.0 – 3.7.3

  • redhat

    openshift_container_platform

  • redhat

    virtualization

References & sources

IDCVE-2019-9636