Name | CVE-2020-8492 |
Description | Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 ... |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
References | DLA-2280-1, ELA-239-1 |
Debian Bugs | 970099 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
python2.7 (PTS) | jessie, jessie (lts) | 2.7.9-2-ds1+deb8u6 | vulnerable |
| stretch | 2.7.13-2+deb9u3 | vulnerable |
| stretch (security) | 2.7.13-2+deb9u4 | vulnerable |
| buster | 2.7.16-2+deb10u1 | vulnerable |
| sid, bullseye | 2.7.18-1 | vulnerable |
python3.4 (PTS) | jessie, jessie (lts) | 3.4.2-1+deb8u10 | fixed |
python3.5 (PTS) | stretch | 3.5.3-1+deb9u1 | vulnerable |
| stretch (security) | 3.5.3-1+deb9u3 | fixed |
python3.7 (PTS) | buster | 3.7.3-2+deb10u2 | fixed |
python3.8 (PTS) | sid | 3.8.7-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[jessie] - python3.4 <postponed> (Minor issue)
[bullseye] - python2.7 <ignored> (Python 2 not covered by security support)
[buster] - python2.7 <no-dsa> (Minor issue)
[stretch] - python2.7 <no-dsa> (Minor issue)
[jessie] - python2.7 <no-dsa> (Minor issue)
https://bugs.python.org/issue39503
https://github.com/python/cpython/pull/18284
https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html
https://github.com/python/cpython/commit/0b297d4ff1c0e4480ad33acae793fbaf4bf015b4 (master)
https://github.com/python/cpython/commit/ea9e240aa02372440be8024acb110371f69c9d41 (3.8-branch)
https://github.com/python/cpython/commit/b57a73694e26e8b2391731b5ee0b1be59437388e (3.7-branch)
https://github.com/python/cpython/commit/69cdeeb93e0830004a495ed854022425b93b3f3e (3.6-branch)
[wheezy] - python2.7 <no-dsa> (Minor issue)