Oval Definition:oval:com.ubuntu.bionic:def:20199636000
Revision Date:2019-03-08Version:1
Title:CVE-2019-9636 on Ubuntu 18.04 LTS (bionic) - medium.
Description:Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-9636
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND Package Information
  • The 'python2.7' package in bionic is affected and needs fixing.
  • OR The 'python3.6' package in bionic is affected and needs fixing.
  • OR NOT While related to the CVE in some way, the 'python3.7' package in bionic is not affected (note: '3.7.3~rc1-1').
  • BACK