HIGH 7.6 Microsoft PoC
CVE-2015-20107
In Python (aka CPython) up to 3.10.8 the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7 3.8 3.9
Microsoft Security Update 2022-Apr: In Python (aka CPython) up to 3.10.8 the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7 3.8 3.9
Affected Products
- cm1 python3 3.7.13-4 on CBL Mariner 1.0
- cm1 python2 2.7.18-11 on CBL Mariner 1.0
- cbl2 python3 3.9.13-5 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2015-20107
- https://nvd.nist.gov/vuln/detail/CVE-2015-20107
This high severity vulnerability with a CVSS score of 7.6 was published on 2022-04-12 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 7.0% (top 6% of all CVEs by exploitation probability). Affected: cm1 python3 3.7.13-4 on CBL Mariner 1.0, cm1 python2 2.7.18-11 on CBL Mariner 1.0, cbl2 python3 3.9.13-5 on CBL Mariner 2.0.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.