PT-2011-2815 · Python+2 · Python+2

Publicado

2011-05-05

·

Atualizado

2019-10-25

·

CVE-2011-1015

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Python versions 2.5 through 2.6 and version 3.0
Description The issue allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI, specifically affecting the is cgi method in CGIHTTPServer.py in the CGIHTTPServer module.
Recommendations For versions 2.5 through 2.6 and version 3.0, consider restricting access to the CGIHTTPServer module until a fix is applied, or apply a patch that corrects the is cgi method to properly handle HTTP GET requests.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1015
DLA-25-1
PSF-2011-1
RHSA-2011:0491
RHSA-2011:0492
RHSA-2011:0554
RHSA-2011_0491
RHSA-2011_0492
RHSA-2011_0554
SUSE-SU-2012_0642-1

Produtos afetados

Python
Red Hat
Suse