漏洞信息详情
Python 命令注入漏洞
漏洞简介
Python是Python基金会的一套开源的、面向对象的程序设计语言。该语言具有可扩展、支持模块和包、支持多种平台等特点。
Python(CPython) 2.7版本中的shutil模块(make_archive函数)存在命令注入漏洞。攻击者可通过输入消息利用该漏洞造成拒绝服务或获取信息。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://bugs.python.org/issue34540
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2018/09/msg00031.html
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2018/09/msg00030.html
来源:UBUNTU
链接:https://usn.ubuntu.com/3817-2/
来源:UBUNTU
链接:https://usn.ubuntu.com/3817-1/
来源:MISC
链接:https://mega.nz/#!JUFiCC4R!mq-jQ8ySFwIhX6WMDujaZuNBfttDVt7DETlfOIQE1ig
来源:CONFIRM
链接:https://bugs.python.org/issue34540
来源:CONFIRM
链接:https://github.com/python/cpython/pull/8985
来源:CONFIRM
链接:https://github.com/python/cpython/pull/8985/commits/add531a1e55b0a739b0f42582f1c9747e5649ace
来源:DEBIAN
链接:https://www.debian.org/security/2018/dsa-4306
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2020/suse-su-20200302-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192050-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192053-1.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192053-2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76802
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/77150
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0397/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2955/
来源:www-01.ibm.com
链接:https://www-01.ibm.com/support/docview.wss?uid=ibm10791595
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10791567
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2955.2/
受影响实体
- Debian Debian_linux:9.0<!--2000-1-1-->
- Debian Debian_linux:8.0<!--2000-1-1-->
补丁
- Python Software Foundation Python 命令注入漏洞的修复措施<!--2018-9-19-->
还没有评论,来说两句吧...