CVE-2017-17522
14.12.2017, 16:29
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting
Vendor | Product | Version |
---|---|---|
python | python | 𝑥 ≤ 3.6.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
jython |
| ||||||||||||||||||||||||||||
python2.6 |
| ||||||||||||||||||||||||||||
python2.7 |
| ||||||||||||||||||||||||||||
python3.2 |
| ||||||||||||||||||||||||||||
python3.4 |
| ||||||||||||||||||||||||||||
python3.5 |
| ||||||||||||||||||||||||||||
python3.6 |
| ||||||||||||||||||||||||||||
python3.7 |
|