CVE-2019-9948

urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mech… (CVE-2019-9948)

criticalEPSS 12%

Description

urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.

Metrics

Severity
critical
no public PoC known
9.1
Source: nvd-v3
95.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
11.8 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2019-03-23 17:07 UTC

Affected operating systems

  • linux

    debian / debian_linux8.0

  • linux

    debian / debian_linux9.0

  • linux

    redhat / enterprise_linux_desktop7.0

  • linux

    redhat / enterprise_linux_desktop8.0

  • linux

    redhat / enterprise_linux_eus8.1

  • linux

    redhat / enterprise_linux_eus8.2

  • linux

    redhat / enterprise_linux_eus8.4

  • linux

    redhat / enterprise_linux_eus8.6

  • linux

    redhat / enterprise_linux_server7.0

  • linux

    redhat / enterprise_linux_server8.0

  • linux

    redhat / enterprise_linux_server_eus8.4

  • linux

    redhat / enterprise_linux_tus8.2

  • linux

    redhat / enterprise_linux_tus8.4

  • linux

    redhat / enterprise_linux_tus8.6

  • linux

    redhat / enterprise_linux_workstation7.0

  • linux

    redhat / enterprise_linux_workstation8.0

  • linux

    opensuse / leap15.0

  • linux

    opensuse / leap42.3

  • linux

    canonical / ubuntu_linux12.04

  • linux

    canonical / ubuntu_linux14.04

  • linux

    canonical / ubuntu_linux16.04

  • linux

    canonical / ubuntu_linux18.04

  • linux

    canonical / ubuntu_linux19.04

  • other

    fedoraproject / fedora29

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • python

    python2.0 – 2.7.17

  • python

    python3.5.0 – 3.5.8

  • python

    python3.6.0 – 3.6.9

  • python

    python3.7.0 – 3.7.4

References & sources

IDCVE-2019-9948