Exposed dangerous method or function in Python - CVE-2019-9948
Published: June 19, 2019 / Updated: July 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to urllib implementation in Python 2.x supports the local_file: scheme. An attacker with ability to control input data, such as URL, can bypass protection mechanisms that blacklist file: URIs and view contents of arbitrary file on the system.
PoC:
urllib.urlopen('local_file:///etc/passwd') Affected software
Amazon Linux AMI
Gentoo Linux
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
Ubuntu
Opensuse
python (Red Hat package)
python2-tkinter (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
python3.11 (Ubuntu package)
python3.8-minimal (Ubuntu package)
python3.9 (Ubuntu package)
python3.8 (Ubuntu package)
python3.9-minimal (Ubuntu package)
python3.6 (Ubuntu package)
python3.6-minimal (Ubuntu package)
python3.7 (Ubuntu package)
python3.7-minimal (Ubuntu package)
python3.11-minimal (Ubuntu package)
python3.5 (Ubuntu package)
python3.5-minimal (Ubuntu package)
python27-python (Red Hat package)
python34
python3
python3-docs
python3.10-minimal (Ubuntu package)
python3.10 (Ubuntu package)
python3.12-minimal (Ubuntu package)
python3.12 (Ubuntu package)
Data Computing Appliance (DCA)
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2019-9948
python (Red Hat package) - addressed in versions 2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6
python2-tkinter (Alpine package) - update to 2.7.17-r0
python3.11 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.8-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.10
python3.9 (Ubuntu package) - update to Ubuntu Pro
python3.8 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.10
python3.9-minimal (Ubuntu package) - update to Ubuntu Pro
python3.6 (Ubuntu package) - update to Ubuntu Pro
python3.6-minimal (Ubuntu package) - update to Ubuntu Pro
python3.7 (Ubuntu package) - update to Ubuntu Pro
python3.7-minimal (Ubuntu package) - update to Ubuntu Pro
python3.11-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
python3.5-minimal (Ubuntu package) - update to Ubuntu Pro
python27-python (Red Hat package) - addressed in versions 2.7.16-6.el6, 2.7.16-6.el7
python34 - addressed in versions 3.4.10-4.el6, 3.4.10-4.el7
python3 - addressed in versions 3.7.4-1.fc29, 3.7.4-1.fc30
python3-docs - addressed in versions 3.7.4-1.fc29, 3.7.4-1.fc30
python3.10-minimal (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.10 (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.12-minimal (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python3.12 (Ubuntu package) - update to 3.12.0-1ubuntu0.1
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
- https://bugs.python.org/issue35907
- https://github.com/python/cpython/pull/11842
- https://github.com/python/cpython/commit/4fe82a8eef7aed60de05bfca0f2c322730ea921e
- https://github.com/python/cpython/commit/4f06dae5d8d4400ba38d8502da620f07d4a5696e
- https://github.com/python/cpython/commit/34bab215596671d0dec2066ae7d7450cd73f638b
Related Security Bulletins
- Multiple vulnerabilities in Python
- OpenSUSE Linux update for python
- OpenSUSE Linux update for python
- Red Hat update for python
- Amazon Linux AMI update for python27
- Slackware Linux update for python
- Red Hat update for python3
- Gentoo update for Python
- Red Hat Enterprise Linux 7 update for python
- Red Hat Enterprise Linux 7 update for python
- Red Hat Enterprise Linux 7 update for python
- Exposed dangerous method or function in python2-tkinter (Alpine package)
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Software Collections update for python27-python
- Ubuntu update for python3.10
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Fedora 30 update for python3, python3-docs
- Fedora 29 update for python3, python3-docs
- Fedora EPEL 6 update for python34
- Fedora EPEL 7 update for python34