CVE-2020-8492
Summary
| CVE | CVE-2020-8492 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-30 19:15:00 UTC |
| Updated | 2023-11-07 03:26:00 UTC |
| Description | Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2280-1] python3.5 security update |
MLIST |
lists.debian.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| [SECURITY] Fedora 32 Update: python36-3.6.11-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: python36-3.6.11-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| USN-4333-1: Python vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] [DLA 3432-1] python2.7 security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 31 Update: python38-3.8.3-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Python: Denial of Service (GLSA 202005-09) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 31 Update: python38-3.8.3-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| USN-4333-2: Python vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| urllib basic auth regex denial of service — Python Security 0.0 documentation |
MISC |
python-security.readthedocs.io |
Exploit, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [SECURITY] Fedora 32 Update: python3-3.8.3-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| [SECURITY] Fedora 31 Update: python36-3.6.11-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| bpo-39503: Fix urllib basic auth regex by vstinner · Pull Request #18284 · python/cpython · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE-2020-8492 Python Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: python3-3.8.3-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Issue 39503: [security][CVE-2020-8492] Denial of service in urllib.request.AbstractBasicAuthHandler - Python tracker |
MISC |
bugs.python.org |
Issue Tracking, Vendor Advisory |
| [SECURITY] Fedora 32 Update: python36-3.6.11-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:0274-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159654 Oracle Enterprise Linux Security Update for python38:3.8 (ELSA-2020-4641)
- 181802 Debian Security Update for python2.7 (DLA 3432-1)
- 198293 Ubuntu Security Notification for Python2.7, Python3.7, Python3.8 Vulnerabilities (USN-4754-3)
- 198611 Ubuntu Security Notification for Python Vulnerabilities (USN-5200-1)
- 296073 Oracle Solaris 11.4 Support Repository Update (SRU) 24.75.2 Missing (CPUJUL2020)
- 356280 Amazon Linux Security Advisory for python38 : ALASPYTHON3.8-2023-006
- 356582 Amazon Linux Security Advisory for python38 : ALAS2PYTHON3.8-2023-006
- 376090 IBM Cognos Analytics Multiple Vulnerabilities (6491661)
- 377257 Alibaba Cloud Linux Security Update for python3 (ALINUX2-SA-2020:0137)
- 377387 Alibaba Cloud Linux Security Update for python3 (ALINUX3-SA-2021:0080)
- 500591 Alpine Linux Security Update for python3
- 504341 Alpine Linux Security Update for python3
- 690114 Free Berkeley Software Distribution (FreeBSD) Security Update for tauthon (c7855866-c511-11eb-ae1d-b42e991fc52e)
- 690464 Free Berkeley Software Distribution (FreeBSD) Security Update for python (2cb21232-fb32-11ea-a929-a4bf014bf5f7)
- 750463 OpenSUSE Security Update for python3 (openSUSE-SU-2020:2333-1)
- 750464 OpenSUSE Security Update for python3 (openSUSE-SU-2020:2332-1)
- 752957 SUSE Enterprise Linux Security Update for python3 (SUSE-SU-2022:4281-1)
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940166 AlmaLinux Security Update for python3 (ALSA-2020:4433)
- 940211 AlmaLinux Security Update for python38:3.8 (ALSA-2020:4641)
- 960347 Rocky Linux Security Update for python38:3.8 (RLSA-2020:4641)