logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2015-20107

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2015-20107

Description:
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Last updated date:
06/30/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/21/2022
Reference url to background

https://bugs.python.org/issue24778

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy