CVE-2011-1521

Description

The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.996

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Python for MAC 2.0Mac
Multiple Vulnerabilities are affected in Python for MAC 2.0.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.1.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.1.2Mac
Multiple Vulnerabilities are affected in Python for MAC 2.1.3Mac
Multiple Vulnerabilities are affected in Python for MAC 2.2Mac
Multiple Vulnerabilities are affected in Python for MAC 2.2.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.2.2Mac
Multiple Vulnerabilities are affected in Python for MAC 2.2.3Mac
Multiple Vulnerabilities are affected in Python for MAC 2.3.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.3.2Mac
Multiple Vulnerabilities are affected in Python for MAC 2.3.3Mac
Multiple Vulnerabilities are affected in Python for MAC 2.3.4Mac
Multiple Vulnerabilities are affected in Python for MAC 2.3.5Mac
Multiple Vulnerabilities are affected in Python for MAC 2.4.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.4.2Mac
Multiple Vulnerabilities are affected in Python for MAC 2.4.3Mac
Multiple Vulnerabilities are affected in Python for MAC 2.4.4Mac
Multiple Vulnerabilities are affected in Python for MAC 2.5.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.5.2Mac
Multiple Vulnerabilities are affected in Python for MAC 2.3.7Mac
Multiple Vulnerabilities are affected in Python for MAC 2.4.6Mac
Multiple Vulnerabilities are affected in Python for MAC 2.6.5Mac
Multiple Vulnerabilities are affected in Python for MAC 3.1Mac
Multiple Vulnerabilities are affected in Python for MAC 3.2Mac
Multiple Vulnerabilities are affected in Python for MAC 2.5.3Mac
Multiple Vulnerabilities are affected in Python for MAC 2.5.4Mac
Multiple Vulnerabilities are affected in Python for MAC 2.6.1Mac
Multiple Vulnerabilities are affected in Python for MAC 2.6.4Mac
Multiple Vulnerabilities are affected in Python for MAC 2.6.6Mac
Multiple Vulnerabilities are affected in Python for MAC 2.6.7Mac
Multiple Vulnerabilities are affected in Python for MAC 2.7.1Mac
Multiple Vulnerabilities are affected in Python for MAC 3.0Mac
Multiple Vulnerabilities are affected in Python for MAC 3.0.1Mac
Multiple Vulnerabilities are affected in Python for MAC 3.1.1Mac
Multiple Vulnerabilities are affected in Python for MAC 3.1.2Mac
Multiple Vulnerabilities are affected in Python for MAC 3.1.3Mac
(RHSA-2011:0554) Moderate: python security, bug fix, and enhancement update python-docs-2.6.6-2.el6.noarch.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7
PATCH-611773Python for MAC 3.13.7

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234