← Back

CVE-2015-20107

nvd nist
Published: Apr 13, 2022Modified: Nov 3, 2025

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Exploitability: 2.8 / Impact: 4.7
Source: NVD

Description

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

Affected (11)

1 product
Python
3 products
Active Iq Unified Manager
Snapcenter
1 product
Fedora
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Python
From 3.10.0 to 3.10.8
From 3.7.0 to 3.7.15
From 3.8.0 to 3.8.15
From 3.9.0 to 3.9.15
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions
All versions
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Version 37

References (59)

Source: cve@mitre.org
ExploitIssue TrackingVendor Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.