CVE-2014-4650
Description
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.019
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| An interactive high-level object-oriented language (USN-2653-1) python3.4_3.4.0-2ubuntu1.1_i386.deb | Linux |
| An interactive high-level object-oriented language (USN-2653-1) python3.4_3.4.0-2ubuntu1.1_amd64.deb | Linux |
| An interactive high-level object-oriented language (USN-2653-1) python3.4-minimal_3.4.0-2ubuntu1.1_i386.deb | Linux |
| An interactive high-level object-oriented language (USN-2653-1) python3.4-minimal_3.4.0-2ubuntu1.1_amd64.deb | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-32bit-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-debuginfo-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-debuginfo-32bit-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-32bit-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-base-32bit-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-debuginfo-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-debuginfo-32bit-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-debugsource-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-curses-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-curses-debuginfo-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-debuginfo-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-debuginfo-32bit-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-debugsource-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-demo-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-devel-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-doc-2.7.9-14.3.noarch.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-doc-pdf-2.7.9-14.3.noarch.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-gdbm-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-gdbm-debuginfo-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-idle-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-tk-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-tk-debuginfo-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-xml-2.7.9-14.1.x86_64.rpm | Linux |
| SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-xml-debuginfo-2.7.9-14.1.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234