CVE-2015-20107

NameCVE-2015-20107
DescriptionIn Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3432-1, DLA-3477-1, DLA-3980-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pypy3 (PTS)bullseye7.3.5+dfsg-2+deb11u2vulnerable
bullseye (security)7.3.5+dfsg-2+deb11u4vulnerable
bookworm7.3.11+dfsg-2+deb12u3fixed
sid, trixie7.3.19+dfsg-2fixed
python2.7 (PTS)bullseye2.7.18-8+deb11u1vulnerable
python3.9 (PTS)bullseye3.9.2-1vulnerable
bullseye (security)3.9.2-1+deb11u3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pypy3source(unstable)7.3.11+dfsg-1
python2.7sourcebuster2.7.16-2+deb10u2DLA-3432-1
python2.7source(unstable)(unfixed)
python3.10source(unstable)3.10.6-1
python3.5source(unstable)(unfixed)
python3.7sourcebuster3.7.3-2+deb10u5DLA-3477-1
python3.7source(unstable)(unfixed)
python3.9sourcebullseye3.9.2-1+deb11u2DLA-3980-1
python3.9source(unstable)(unfixed)

Notes

[stretch] - python3.5 <no-dsa> (Minor issue)
[bullseye] - python2.7 <ignored> (Python 2.7 in Bullseye not covered by security support)
[stretch] - python2.7 <no-dsa> (Minor issue)
[bullseye] - pypy3 <postponed> (Minor issue)
https://bugs.python.org/issue24778
https://github.com/python/cpython/issues/68966
https://github.com/python/cpython/pull/91993

Search for package or bug name: Reporting problems