CVE-2016-1000110
27.11.2019, 17:15
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
Vendor | Product | Version |
---|---|---|
python | python | 2.7.0 ≤ 𝑥 < 2.7.13 |
python | python | 3.3.0 ≤ 𝑥 < 3.3.7 |
python | python | 3.4.0 ≤ 𝑥 < 3.4.6 |
python | python | 3.5.0 ≤ 𝑥 < 3.5.3 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python2.7 |
| ||||||||||||||||||||||||||||||||
python3.2 |
| ||||||||||||||||||||||||||||||||
python3.4 |
| ||||||||||||||||||||||||||||||||
python3.5 |
|
Common Weakness Enumeration
References