Python CGIHTTPServer Module Path Separators Handling Information Disclosure Vulnerability
BID:68147
Info
Python CGIHTTPServer Module Path Separators Handling Information Disclosure Vulnerability
| Bugtraq ID: | 68147 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-4650 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2014 12:00AM |
| Updated: | Jul 06 2016 01:15PM |
| Credit: | Till Maas |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Linux 0 |
| Not Vulnerable: | |
Discussion
Python CGIHTTPServer Module Path Separators Handling Information Disclosure Vulnerability
Python CGIHTTPServer module is prone to an information-disclosure vulnerability.
Exploiting this issue can allow attackers to gain access to potentially sensitive information contained in arbitrary scripts. Successful exploits may lead to other attacks.
Python 2.7.5 and 3.3.4 are vulnerable; other versions may also be affected.
Python CGIHTTPServer module is prone to an information-disclosure vulnerability.
Exploiting this issue can allow attackers to gain access to potentially sensitive information contained in arbitrary scripts. Successful exploits may lead to other attacks.
Python 2.7.5 and 3.3.4 are vulnerable; other versions may also be affected.
Exploit / POC
Python CGIHTTPServer Module Path Separators Handling Information Disclosure Vulnerability
Attackers can exploit this issue with a web browser.
Attackers can exploit this issue with a web browser.
Solution / Fix
Python CGIHTTPServer Module Path Separators Handling Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.