CVE-2024-6923

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
Configurations

No configuration.

History

21 Nov 2024, 09:50

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/08/01/3 -
  • () http://www.openwall.com/lists/oss-security/2024/08/02/2 -
  • () https://security.netapp.com/advisory/ntap-20240926-0003/ -

04 Sep 2024, 21:15

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147 -
  • () https://github.com/python/cpython/commit/b158a76ce094897c870fb6b3de62887b7ccc33f1 -
  • () https://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6 -
  • () https://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533 -

07 Aug 2024, 15:15

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7 -
  • () https://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0 -
Summary
  • (es) Existe una vulnerabilidad de gravedad MEDIA que afecta a CPython. El módulo de correo electrónico no citaba correctamente las nuevas líneas para los encabezados de correo electrónico al serializar un mensaje de correo electrónico, lo que permitía la inyección de encabezado cuando se serializa un correo electrónico.

01 Aug 2024, 19:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-94

01 Aug 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-01 14:15

Updated : 2024-11-21 09:50


NVD link : CVE-2024-6923

Mitre link : CVE-2024-6923

CVE.ORG link : CVE-2024-6923


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')