PT-2011-2815 · Python+2 · Python+2

Published

2011-05-05

·

Updated

2019-10-25

·

CVE-2011-1015

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Python versions 2.5 through 2.6 and version 3.0
Description The issue allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI, specifically affecting the is cgi method in CGIHTTPServer.py in the CGIHTTPServer module.
Recommendations For versions 2.5 through 2.6 and version 3.0, consider restricting access to the CGIHTTPServer module until a fix is applied, or apply a patch that corrects the is cgi method to properly handle HTTP GET requests.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1015
DLA-25-1
PSF-2011-1
RHSA-2011:0491
RHSA-2011:0492
RHSA-2011:0554
RHSA-2011_0491
RHSA-2011_0492
RHSA-2011_0554
SUSE-SU-2012_0642-1

Affected Products

Python
Red Hat
Suse