低危 Oracle Sun ZFS Storage Appliance Kit 38937 Operating System Image 凭证管理漏洞

CVE编号

CVE-2019-9636

利用情况

暂无

补丁情况

官方补丁

披露时间

2019-03-09
漏洞描述
Python 2.6.x through 2.7.16 和 3.x through 3.7.2受到以下因素的影响:在NFKC规范化期间,Unicode编码(使用不正确的netloc)处理不当。其影响是:信息泄露(根据给定主机名缓存的凭据,cookie等)。组件是:urllib.parse.urlsplit,urllib.parse.urlparse。攻击媒介是:可能会错误地解析特制URL以查找Cookie或身份验证数据,并将该信息发送到与正确解析时不同的主机。

解决建议
厂商已发布漏洞修复程序,请及时关注更新:
https://github.com/python/cpython/pull/12201/files
参考链接
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
http://www.securityfocus.com/bid/107400
https://access.redhat.com/errata/RHBA-2019:0763
https://access.redhat.com/errata/RHBA-2019:0764
https://access.redhat.com/errata/RHBA-2019:0959
https://access.redhat.com/errata/RHSA-2019:0710
https://access.redhat.com/errata/RHSA-2019:0765
https://access.redhat.com/errata/RHSA-2019:0806
https://access.redhat.com/errata/RHSA-2019:0902
https://access.redhat.com/errata/RHSA-2019:0981
https://access.redhat.com/errata/RHSA-2019:0997
https://access.redhat.com/errata/RHSA-2019:1467
https://access.redhat.com/errata/RHSA-2019:2980
https://access.redhat.com/errata/RHSA-2019:3170
https://bugs.python.org/issue36216
https://github.com/python/cpython/pull/12201
https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html
https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html
https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html
https://security.gentoo.org/glsa/202003-26
https://security.netapp.com/advisory/ntap-20190517-0001/
https://usn.ubuntu.com/4127-1/
https://usn.ubuntu.com/4127-2/
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2022.html
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 python python * From
(including)
2.7.0
Up to
(including)
2.7.16
运行在以下环境
应用 python python * From
(including)
3.0.0
Up to
(including)
3.7.2
运行在以下环境
系统 alibaba_cloud_linux_2.1903 python * Up to
(excluding)
2.7.5-77.1.al7
运行在以下环境
系统 alibaba_cloud_linux_3 python3 * Up to
(excluding)
3.6.8-39.1.al8
运行在以下环境
系统 alpine_3.10 python2 * Up to
(excluding)
2.7.16-r1
运行在以下环境
系统 alpine_3.11 python2 * Up to
(excluding)
2.7.16-r1
运行在以下环境
系统 alpine_3.12 python2 * Up to
(excluding)
2.7.16-r1
运行在以下环境
系统 alpine_3.13 python2 * Up to
(excluding)
2.7.16-r1
运行在以下环境
系统 alpine_3.14 python2 * Up to
(excluding)
2.7.16-r1
运行在以下环境
系统 alpine_3.15 python2 * Up to
(excluding)
2.7.16-r1
运行在以下环境
系统 alpine_3.6 python3 * Up to
(excluding)
3.6.8-r0
运行在以下环境
系统 alpine_3.7 python2 * Up to
(excluding)
2.7.15-r2
运行在以下环境
系统 alpine_3.8 python2 * Up to
(excluding)
2.7.15-r2
运行在以下环境
系统 alpine_3.9 python2 * Up to
(excluding)
2.7.16-r1
运行在以下环境
系统 amazon_2 python * Up to
(excluding)
2.7.16-1.amzn2.0.1
运行在以下环境
系统 amazon_AMI python35 * Up to
(excluding)
3.5.7-1.22.amzn1
运行在以下环境
系统 anolis_os_7 python * Up to
(excluding)
2.7.5-90
运行在以下环境
系统 anolis_os_8 python3 * Up to
(excluding)
3.6.8-47.0.1
运行在以下环境
系统 centos_6 python * Up to
(excluding)
2.6.6-68.el6_10
运行在以下环境
系统 centos_7 python * Up to
(excluding)
2.7.5-77.el7_6
运行在以下环境
系统 debian_10 python2.7 * Up to
(excluding)
2.7.16-2
运行在以下环境
系统 debian_11 python2.7 * Up to
(excluding)
2.7.16-2
运行在以下环境
系统 fedora_28 python3 * Up to
(excluding)
3.6.8-3.fc28
运行在以下环境
系统 fedora_29 python3 * Up to
(excluding)
3.7.2-5.fc29
运行在以下环境
系统 fedora_30 python3 * Up to
(excluding)
3.7.2-8.fc30
运行在以下环境
系统 fedora_31 python34 * Up to
(excluding)
3.4.10-5.fc31
运行在以下环境
系统 fedora_EPEL_6 python34 * Up to
(excluding)
3.4.10-4.el6
运行在以下环境
系统 fedora_EPEL_7 python36 * Up to
(excluding)
3.6.8-1.el7
运行在以下环境
系统 kylinos_aarch64_V10 python * Up to
(excluding)
2.7.5-90.el7.ns7.01
运行在以下环境
系统 kylinos_x86_64_V10 python * Up to
(excluding)
2.7.5-90.el7.ns7.01
运行在以下环境
系统 opensuse_Leap_15.0 python * Up to
(excluding)
2.7.14-lp150.6.10.1
运行在以下环境
系统 opensuse_Leap_15.1 python3 * Up to
(excluding)
3.6.10-lp151.6.7.1
运行在以下环境
系统 opensuse_Leap_42.3 python * Up to
(excluding)
2.7.13-27.15.1
运行在以下环境
系统 oracle_6 python * Up to
(excluding)
2.6.6-68.0.1.el6_10
运行在以下环境
系统 oracle_7 python * Up to
(excluding)
2.7.5-77.0.1.el7_6
运行在以下环境
系统 oracle_8 python3-libs * Up to
(excluding)
3.6.8-2.0.1.el8_0
运行在以下环境
系统 redhat_7 python * Up to
(excluding)
2.7.5-77.el7_6
运行在以下环境
系统 redhat_8 python3-idle * Up to
(excluding)
3.6.8-2.el8_0
运行在以下环境
系统 rocky_linux_8 python-lxml * Up to
(excluding)
0.23-19.el8
运行在以下环境
系统 suse_12_SP3 python * Up to
(excluding)
2.7.13-28.26.1
运行在以下环境
系统 suse_12_SP4 python * Up to
(excluding)
2.7.13-28.26.1
运行在以下环境
系统 suse_12_SP5 python36 * Up to
(excluding)
3.6.10-4.3.5
运行在以下环境
系统 ubuntu_16.04 python2.7 * Up to
(excluding)
3.5.2-2ubuntu0~16.04.8
运行在以下环境
系统 ubuntu_18.04 python2.7 * Up to
(excluding)
2.7.15-4ubuntu4~18.04.1
阿里云评分
3.1
  • 攻击路径
    远程
  • 攻击复杂度
    复杂
  • 权限要求
    无需权限
  • 影响范围
    有限影响
  • EXP成熟度
    未验证
  • 补丁情况
    官方补丁
  • 数据保密性
    无影响
  • 数据完整性
    无影响
  • 服务器危害
    无影响
  • 全网数量
    100
CWE-ID 漏洞类型
NVD-CWE-noinfo
阿里云安全产品覆盖情况