Arbitrary Code Injection Affecting python-tk package, versions <2.7.17-7.44.4
Threat Intelligence
EPSS
0.31% (71st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES152-PYTHONTK-2697958
- published 14 Apr 2022
- disclosed 2 Nov 2020
Introduced: 2 Nov 2020
CVE-2020-26116 Open this link in a new tabHow to fix?
Upgrade SLES:15.2 python-tk to version 2.7.17-7.44.4 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream python-tk package and not the python-tk package as distributed by SLES.
See How to fix? for SLES:15.2 relevant fixed versions and status.
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
References
- https://www.suse.com/security/cve/CVE-2020-26116.html
- https://bugzilla.suse.com/1177120
- https://bugzilla.suse.com/1177211
- https://bugzilla.suse.com/1192361
- https://bugs.python.org/issue39603
- https://python-security.readthedocs.io/vuln/http-header-injection-method.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/
- https://usn.ubuntu.com/4581-1/
- https://security.netapp.com/advisory/ntap-20201023-0001/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/
- https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html
- https://security.gentoo.org/glsa/202101-18
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/
CVSS Scores
version 3.1