漏洞信息详情

Redis Labs Redis和Python 注入漏洞

  • CNNVD编号:CNNVD-201903-875
  • 危害等级: 中危
  • CVE编号: CVE-2019-9947
  • 漏洞类型: 注入
  • 发布时间: 2019-03-23
  • 威胁类型: 远程
  • 更新时间: 2022-02-18
  • 厂        商:
  • 漏洞来源: Red Hat,Gentoo

漏洞简介

Python是一套开源的、面向对象的程序设计语言。该语言具有可扩展、支持模块和包、支持多种平台等特点。urllib是其中的一个用于处理URL的模块。urllib2是其中的一个用于获取URL(统一资源定位符)的模块。Redis是一套开源的使用ANSI C编写、支持网络、可基于内存亦可持久化的日志型、键值(Key-Value)存储数据库,并提供多种语言的API。

Python 2.x版本至2.7.16版本中的urllib2和Python 3.x版本至3.7.2版本中的urllib存在注入漏洞。该漏洞源于用户输入构造命令、数据结构或记录的操作过程中,网络系统或产品缺乏对用户输入数据的正确验证,未过滤或未正确过滤掉其中的特殊元素,导致系统或产品产生解析或解释方式错误。

漏洞公告

目前厂商已发布升级补丁以修复漏洞,补丁获取链接:

https://bugs.python.org/issue35906

参考网址

来源:GENTOO

链接:https://security.gentoo.org/glsa/202003-26

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:3725

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html

来源:bugs.python.org

链接:https://bugs.python.org/issue35906

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:3520

来源:UBUNTU

链接:https://usn.ubuntu.com/4127-1/

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:1260

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:2030

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:3335

来源:UBUNTU

链接:https://usn.ubuntu.com/4127-2/

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2021/02/04/2

来源:CONFIRM

链接:https://security.netapp.com/advisory/ntap-20190404-0004/

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191352-2.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200302-1.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-201914246-1.html

来源:lists.debian.org

链接:https://lists.debian.org/debian-lts-announce/2019/06/msg00026.html

来源:www.ibm.com

链接:https://www.ibm.com/support/pages/node/1115643

来源:www.ibm.com

链接:https://www.ibm.com/support/pages/node/1115649

来源:www.ibm.com

链接:https://www.ibm.com/support/pages/node/1116357

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191352-1.html

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:1260

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4645/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4479/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/157141/Red-Hat-Security-Advisory-2020-1346-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.2421/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-all-python-publicly-disclosed-vulnerability/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.1840/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.1880/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2592/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1281/

来源:www.ibm.com

链接:https://www.ibm.com/support/pages/node/1167106

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1174/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1243/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4479.2/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2022.0696

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/156748/Gentoo-Linux-Security-Advisory-202003-26.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/157222/Red-Hat-Security-Advisory-2020-1462-01.html

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Python-urllib2-information-disclosure-via-CRLF-Injection-HTTP-Redis-28847

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.4237/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-resilient-is-vulnerable-to-using-python-component-with-known-vulnerabilities-in-rhel-7-4/

来源:www.ibm.com

链接:https://www.ibm.com/support/pages/node/1115655

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.0397/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.0013/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2290/

来源:www.ibm.com

链接:https://www.ibm.com/support/pages/node/1146574

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-9947

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-python-affect-ibm-operations-analytics-predictive-insights-cve-2019-9948-cve-2019-9947/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1341/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/153000/Red-Hat-Security-Advisory-2019-1260-01.html

受影响实体

    暂无


漏洞信息快速查询

相关漏洞

更多