CVE-2016-1000110
27.11.2019, 17:15
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
| Vendor | Product | Version |
|---|---|---|
| python | python | 2.7.0 ≤ 𝑥 < 2.7.13 |
| python | python | 3.3.0 ≤ 𝑥 < 3.3.7 |
| python | python | 3.4.0 ≤ 𝑥 < 3.4.6 |
| python | python | 3.5.0 ≤ 𝑥 < 3.5.3 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python2.7 |
| ||||||||||||||||||||||||||||||||
| python3.2 |
| ||||||||||||||||||||||||||||||||
| python3.4 |
| ||||||||||||||||||||||||||||||||
| python3.5 |
|
Common Weakness Enumeration
References