PT-2016-4502 · Python+5 · Python+5

Andreas Stieger

·

Published

2016-07-25

·

Updated

2024-06-15

·

CVE-2016-1000110

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Python versions prior to 2.7.12
Description The issue concerns a variable name clash in a CGI script, potentially allowing a remote attacker to redirect HTTP requests. This is related to the HTTP PROXY variable.
Recommendations For versions prior to 2.7.12, consider updating to version 2.7.12 or later to resolve the issue. As a temporary workaround, restrict access to CGI scripts that use the HTTP PROXY variable until a patch is applied. Avoid using the HTTP PROXY variable in affected CGI scripts until the issue is resolved.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2598
ALT-PU-2017-2851
CESA-2016_1626
CVE-2016-1000110
MGASA-2016-0296
OPENSUSE-SU-2020:0086-1
OPENSUSE-SU-2020_0086-1
OPENSUSE-SU-2024:11202-1
OPENSUSE-SU-2024:11284-1
PSF-2019-2
RHSA-2016:1626
RHSA-2016:1627
RHSA-2016:1628
RHSA-2016:1629
RHSA-2016:1630
RHSA-2016_1626
SUSE-SU-2016:2106-1
SUSE-SU-2016:2270-1
SUSE-SU-2016:2653-1
SUSE-SU-2016:2859-1
SUSE-SU-2019:0223-1
SUSE-SU-2020:0114-1
SUSE-SU-2020:0234-1
USN-3134-1

Affected Products

Alt Linux
Centos
Python
Red Hat
Suse
Ubuntu