QID 378567

QID 378567: Python Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple

The e-mail module of Python 0 - 2.7.18, 3.x - 3.11 incorrectly parses e-mail addresses which contain a special character. This vulnerability allows attackers to send messages from e-ail addresses that would otherwise be rejected.

Affected version
Python version 0 to 2.7.18 Python version 3.x to 3.11

This vulnerability allows attackers to send messages from e-ail addresses that would otherwise be rejected.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to the latest supported python releases to remediate this vulnerability.
    For latest release visit here.

    CVEs related to QID 378567

    Software Advisories
    Advisory ID Software Component Link