低危 Oracle Sun ZFS Storage Appliance Kit 38937 Operating System Image 凭证管理漏洞

CVE编号

CVE-2019-9636

利用情况

暂无

补丁情况

官方补丁

披露时间

2019-03-09 10:29:00
漏洞描述
Python 2.6.x through 2.7.16 和 3.x through 3.7.2受到以下因素的影响:在NFKC规范化期间,Unicode编码(使用不正确的netloc)处理不当。其影响是:信息泄露(根据给定主机名缓存的凭据,cookie等)。组件是:urllib.parse.urlsplit,urllib.parse.urlparse。攻击媒介是:可能会错误地解析特制URL以查找Cookie或身份验证数据,并将该信息发送到与正确解析时不同的主机。
解决建议
厂商已发布漏洞修复程序,请及时关注更新:
https://github.com/python/cpython/pull/12201/files
参考链接
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
http://www.securityfocus.com/bid/107400
https://access.redhat.com/errata/RHBA-2019:0763
https://access.redhat.com/errata/RHBA-2019:0764
https://access.redhat.com/errata/RHBA-2019:0959
https://access.redhat.com/errata/RHSA-2019:0710
https://access.redhat.com/errata/RHSA-2019:0765
https://access.redhat.com/errata/RHSA-2019:0806
https://access.redhat.com/errata/RHSA-2019:0902
https://access.redhat.com/errata/RHSA-2019:0981
https://access.redhat.com/errata/RHSA-2019:0997
https://access.redhat.com/errata/RHSA-2019:1467
https://access.redhat.com/errata/RHSA-2019:2980
https://access.redhat.com/errata/RHSA-2019:3170
https://bugs.python.org/issue36216
https://github.com/python/cpython/pull/12201
https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html
https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html
https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html
https://security.gentoo.org/glsa/202003-26
https://security.netapp.com/advisory/ntap-20190517-0001/
https://usn.ubuntu.com/4127-1/
https://usn.ubuntu.com/4127-2/
https://www.oracle.com/security-alerts/cpujan2020.html
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 python python * From
(including)
2.7.0
Up to
(including)
2.7.16
运行在以下环境
应用 python python * From
(including)
3.0.0
Up to
(including)
3.7.2
2
运行在以下环境
系统 amazon_2 python * Up to
(excluding)
2.7.16-1.amzn2.0.1
3
运行在以下环境
系统 alpine_3.6 python * Up to
(excluding)
3.6.8-r0
4
运行在以下环境
系统 alpine_3.9 python * Up to
(excluding)
2.7.16-r1
5
运行在以下环境
系统 alpine_edge python * Up to
(excluding)
2.7.16-r1
6
运行在以下环境
系统 alpine_3.13 python * Up to
(excluding)
2.7.16-r1
7
运行在以下环境
系统 alpine_3.12 python * Up to
(excluding)
2.7.16-r1
8
运行在以下环境
系统 amazon_AMI python * Up to
(excluding)
3.4.10-1.49.amzn1
9
运行在以下环境
系统 alpine_3.7 python * Up to
(excluding)
3.6.8-r0
10
运行在以下环境
系统 alpine_3.8 python * Up to
(excluding)
3.6.8-r0
11
运行在以下环境
系统 debian_8 python * Up to
(excluding)
2.7.9-2+deb8u1
12
运行在以下环境
系统 debian_9 python * Up to
(excluding)
2.7.13-2+deb9u4
13
运行在以下环境
系统 alpine_3.10 python * Up to
(excluding)
2.7.16-r1
14
运行在以下环境
系统 alpine_3.11 python * Up to
(excluding)
2.7.16-r1
15
运行在以下环境
系统 suse_12_SP5 python * Up to
(excluding)
3.6.10-4.3.5
16
运行在以下环境
系统 fedora_30 python * Up to
(excluding)
3.5.8-2.fc30
17
运行在以下环境
系统 fedora_29 python * Up to
(excluding)
3.5.8-2.fc29
18
运行在以下环境
系统 fedora_31 python * Up to
(excluding)
3.4.10-5.fc31
19
运行在以下环境
系统 fedora_28 python * Up to
(excluding)
3.5.7-1.fc28
20
运行在以下环境
系统 suse_12_SP3 python * Up to
(excluding)
3.4.6-25.24.1
21
运行在以下环境
系统 suse_12_SP4 python * Up to
(excluding)
3.4.6-25.24.1
22
运行在以下环境
系统 opensuse_Leap_15.0 python * Up to
(excluding)
3.6.5-lp150.2.10.1
23
运行在以下环境
系统 centos_6 python * Up to
(excluding)
2.6.6-68.el6_10
24
运行在以下环境
系统 oracle_6 python * Up to
(excluding)
2.6.6-68.0.1.el6_10
25
运行在以下环境
系统 centos_7 python * Up to
(excluding)
2.7.5-77.el7_6
26
运行在以下环境
系统 oracle_7 python * Up to
(excluding)
2.7.5-77.0.1.el7_6
27
运行在以下环境
系统 alibaba_cloud_linux_2.1903 python * Up to
(excluding)
2.7.5-77.1.al7
28
运行在以下环境
系统 oracle_8 python * Up to
(excluding)
3.6.8-15.1.0.1.el8
29
运行在以下环境
系统 fedora_EPEL_7 python * Up to
(excluding)
3.6.8-1.el7
30
运行在以下环境
系统 fedora_EPEL_6 python * Up to
(excluding)
3.4.10-4.el6
31
运行在以下环境
系统 opensuse_Leap_15.1 python * Up to
(excluding)
3.6.10-lp151.6.7.1
32
运行在以下环境
系统 opensuse_Leap_42.3 python * Up to
(excluding)
3.4.6-12.10.1
阿里云评分
3.1
  • 攻击路径
    远程
  • 攻击复杂度
    复杂
  • 权限要求
    无需权限
  • 影响范围
    有限影响
  • EXP成熟度
    未验证
  • 补丁情况
    官方补丁
  • 数据保密性
    无影响
  • 数据完整性
    无影响
  • 服务器危害
    无影响
  • 全网数量
    100
CWE-ID 漏洞类型
NVD-CWE-noinfo
阿里云安全产品覆盖情况