CVE-2014-4650

Description

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.019

Associated Vulnerability

VulnerabilityOS Platform
An interactive high-level object-oriented language (USN-2653-1) python3.4_3.4.0-2ubuntu1.1_i386.debLinux
An interactive high-level object-oriented language (USN-2653-1) python3.4_3.4.0-2ubuntu1.1_amd64.debLinux
An interactive high-level object-oriented language (USN-2653-1) python3.4-minimal_3.4.0-2ubuntu1.1_i386.debLinux
An interactive high-level object-oriented language (USN-2653-1) python3.4-minimal_3.4.0-2ubuntu1.1_amd64.debLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-32bit-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-debuginfo-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) libpython2_7-1_0-debuginfo-32bit-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-32bit-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-base-32bit-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-debuginfo-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-debuginfo-32bit-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-base-debugsource-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-curses-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-curses-debuginfo-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-debuginfo-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-debuginfo-32bit-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-debugsource-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-demo-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-devel-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-doc-2.7.9-14.3.noarch.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-doc-pdf-2.7.9-14.3.noarch.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-gdbm-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-gdbm-debuginfo-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Server 12 ) python-idle-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-tk-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-tk-debuginfo-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-xml-2.7.9-14.1.x86_64.rpmLinux
SUSE-SU-2015:1344-1(SUSE Linux Enterprise Desktop 12 ) python-xml-debuginfo-2.7.9-14.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234