CVE-2015-20107

NameCVE-2015-20107
DescriptionIn Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python2.7 (PTS)stretch2.7.13-2+deb9u3vulnerable
stretch (security)2.7.13-2+deb9u6vulnerable
buster2.7.16-2+deb10u1vulnerable
bullseye2.7.18-8vulnerable
bookworm, sid2.7.18-13.1vulnerable
python3.10 (PTS)bookworm3.10.4-1vulnerable
sid3.10.4-4vulnerable
python3.5 (PTS)stretch3.5.3-1+deb9u1vulnerable
stretch (security)3.5.3-1+deb9u5vulnerable
python3.7 (PTS)buster3.7.3-2+deb10u3vulnerable
python3.9 (PTS)bullseye3.9.2-1vulnerable
bookworm, sid3.9.12-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python2.7source(unstable)(unfixed)
python3.10source(unstable)(unfixed)
python3.5source(unstable)(unfixed)
python3.7source(unstable)(unfixed)
python3.9source(unstable)(unfixed)

Notes

[bullseye] - python3.9 <no-dsa> (Minor issue)
[buster] - python3.7 <no-dsa> (Minor issue)
[stretch] - python3.5 <no-dsa> (Minor issue)
[bullseye] - python2.7 <ignored> (Python 2.7 in Bullseye not covered by security support)
[buster] - python2.7 <no-dsa> (Minor issue)
[stretch] - python2.7 <ignored> (Python 2.7 in stretch LTS not covered as a runtime concern)
https://bugs.python.org/issue24778
https://github.com/python/cpython/issues/68966
https://github.com/python/cpython/pull/91542

Search for package or bug name: Reporting problems