Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2021.0054
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2021-0054)
Zusammenfassung:The remote host is missing an update for the 'python-pip' package(s) announced via the MGASA-2021-0054 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'python-pip' package(s) announced via the MGASA-2021-0054 advisory.

Vulnerability Insight:
It was discovered that pip did not properly sanitize the filename during pip
install. A remote attacker could possible use this issue to read and write
arbitrary files on the host filesystem as root, resulting in a directory
traversal attack (CVE-2019-20916).

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP
request method, as demonstrated by inserting CR and LF control characters in
the first argument of putrequest(). The python-pip package bundles a copy of
python-urllib3, which was affected by this issue. The bundled copy was
patched to fix the issue (CVE-2020-26137).

Affected Software/OS:
'python-pip' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-20916
https://github.com/gzpan123/pip/commit/a4c735b14a62f9cb864533808ac63936704f2ace
https://github.com/pypa/pip/compare/19.1.1...19.2
https://github.com/pypa/pip/issues/6413
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.debian.org/debian-lts-announce/2020/09/msg00010.html
SuSE Security Announcement: openSUSE-SU-2020:1598 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00005.html
SuSE Security Announcement: openSUSE-SU-2020:1613 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00010.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-26137
https://bugs.python.org/issue39603
https://github.com/urllib3/urllib3/commit/1dd69c5c5982fae7c87a620d487c2ebf7a6b436b
https://github.com/urllib3/urllib3/pull/1800
https://www.oracle.com/security-alerts/cpuoct2021.html
https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html
https://usn.ubuntu.com/4570-1/
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.