Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.118185
Category:General
Title:Python < 3.6.13, 3.7.x < 3.7.10, 3.8.x < 3.8.7, 3.9.x < 3.9.1 Python Issue (bpo-41944) - Linux
Summary:Python is prone to a remote code execution (RCE); vulnerability.
Description:Summary:
Python is prone to a remote code execution (RCE)
vulnerability.

Vulnerability Insight:
By default, the tests are not run with network resources enabled
and so the Python test suite is safe. But if the Python test suite is run explicitly with the
'network' resource enabled (-u network or -u all command line option), the CJK codecs tests of the
Python test suite run eval() on content received via HTTP from pythontest.net.

Vulnerability Impact:
If an attacker can compromise the pythontest.net server, they gain
arbitrary code execution on all buildbots.

If an attacker has control over the network connection of a machine running the Python test suite,
they gain arbitrary code execution there.

Affected Software/OS:
Python prior to version 3.6.13, versions 3.7.x prior to 3.7.10,
3.8.x prior to 3.8.7 and 3.9.x prior to 3.9.1.

Solution:
Update to version 3.6.13, 3.7.10, 3.8.7, 3.9.1 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-27619
https://security.netapp.com/advisory/ntap-20201123-0004/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/
https://security.gentoo.org/glsa/202402-04
https://bugs.python.org/issue41944
https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8
https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9
https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33
https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794
https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E
CopyrightCopyright (C) 2021 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.