6.4
CVSSv2

CVE-2011-1521

Published: 24/05/2011 Updated: 25/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The urllib and urllib2 modules in Python 2.x prior to 2.7.2 and 3.x prior to 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote malicious users to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python python 2.5.2

python python 2.1.2

python python 2.3.3

python python 2.4.4

python python 2.4.2

python python 2.5.4

python python 2.4.6

python python 2.6.7

python python 2.3.2

python python 2.3.1

python python 2.4.3

python python 2.3.5

python python 2.5.1

python python 2.3.7

python python 2.1.3

python python 2.1

python python 2.2.1

python python 2.2.2

python python 2.2.3

python python 2.4.1

python python 2.0.1

python python 2.6.6

python python 2.6.5

python python 2.5.3

python python 2.6.1

python python 2.2

python python 2.3.4

python python 2.1.1

python python 2.0

python python 2.6.4

python python 2.7.1

python python 3.1.2

python python 3.0.1

python python 3.1

python python 3.2

python python 3.1.1

python python 3.0

python python 3.1.3

Vendor Advisories

Debian Bug report logs - #628453 CVE-2011-1521: information disclosure Package: python31; Maintainer for python31 is (unknown); Reported by: Steffen Joeris <white@debianorg> Date: Sun, 29 May 2011 03:42:01 UTC Severity: grave Tags: security Fixed in version 313-1+rm Done: Debian FTP Masters <ftpmaster@ftp-master ...
Several security issues were fixed in Python 27 ...
Applications using certain Python 3 modules could be made to crash or expose sensitive information over the network ...
Several security issues were fixed in Python 24 ...
Several security issues were fixed in Python 25 ...
Several security issues were fixed in Python 26 ...