PT-2016-4502 · Python+5 · Python+5

Andreas Stieger

·

Publicado

2016-07-25

·

Atualizado

2024-06-15

·

CVE-2016-1000110

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Python versions prior to 2.7.12
Description The issue concerns a variable name clash in a CGI script, potentially allowing a remote attacker to redirect HTTP requests. This is related to the HTTP PROXY variable.
Recommendations For versions prior to 2.7.12, consider updating to version 2.7.12 or later to resolve the issue. As a temporary workaround, restrict access to CGI scripts that use the HTTP PROXY variable until a patch is applied. Avoid using the HTTP PROXY variable in affected CGI scripts until the issue is resolved.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2598
ALT-PU-2017-2851
CESA-2016_1626
CVE-2016-1000110
MGASA-2016-0296
OPENSUSE-SU-2020:0086-1
OPENSUSE-SU-2020_0086-1
OPENSUSE-SU-2024:11202-1
OPENSUSE-SU-2024:11284-1
PSF-2019-2
RHSA-2016:1626
RHSA-2016:1627
RHSA-2016:1628
RHSA-2016:1629
RHSA-2016:1630
RHSA-2016_1626
SUSE-SU-2016:2106-1
SUSE-SU-2016:2270-1
SUSE-SU-2016:2653-1
SUSE-SU-2016:2859-1
SUSE-SU-2019:0223-1
SUSE-SU-2020:0114-1
SUSE-SU-2020:0234-1
USN-3134-1

Produtos afetados

Alt Linux
Centos
Python
Red Hat
Suse
Ubuntu