CVE-2023-27043

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappontap_select_deploy_administration_utility
-
pythonpython
𝑥
≤ 2.7.18
pythonpython
3.0 ≤
𝑥
< 3.8.20
pythonpython
3.9.0 ≤
𝑥
< 3.9.20
pythonpython
3.10.0 ≤
𝑥
< 3.10.15
pythonpython
3.11.0 ≤
𝑥
< 3.11.10
pythonpython
3.12.0 ≤
𝑥
< 3.12.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pypy3
bullseye
ignored
bookworm
postponed
buster
postponed
bullseye (security)
7.3.5+dfsg-2+deb11u4
fixed
sid
7.3.17+dfsg-3
fixed
trixie
7.3.17+dfsg-3
fixed
python2.7
bullseye
vulnerable
bookworm
postponed
buster
postponed
python3.11
bookworm
postponed
buster
postponed
bullseye
ignored
bookworm (security)
vulnerable
python3.12
sid
3.12.8-3
fixed
trixie
3.12.8-3
fixed
bookworm
postponed
buster
postponed
bullseye
ignored
python3.9
bullseye
ignored
bookworm
postponed
buster
postponed
bullseye (security)
3.9.2-1+deb11u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
ignored
jammy
Fixed 2.7.18-13ubuntu1.2+esm3
released
focal
Fixed 2.7.18-1~20.04.4+esm3
released
bionic
Fixed 2.7.17-1~18.04ubuntu1.13+esm6
released
xenial
Fixed 2.7.12-1ubuntu0~16.04.18+esm11
released
trusty
Fixed 2.7.6-8ubuntu0.6+esm20
released
python3.10
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
ignored
jammy
Fixed 3.10.12-1~22.04.6
released
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.11
oracular
dne
noble
dne
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needed
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.12
oracular
not-affected
noble
Fixed 3.12.3-1ubuntu0.2
released
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.13
oracular
not-affected
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.4
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
ignored
python3.5
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
Fixed 3.5.2-2ubuntu0~16.04.13+esm15
released
trusty
Fixed 3.5.2-2ubuntu0~16.04.4~14.04.1+esm3
released
python3.6
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
needed
xenial
dne
trusty
dne
python3.7
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
needed
xenial
dne
trusty
dne
python3.8
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
Fixed 3.8.10-0ubuntu1~20.04.12
released
bionic
needed
xenial
dne
trusty
dne
python3.9
oracular
dne
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
needed
bionic
dne
xenial
dne
trusty
dne
References