Lucene search

K
freebsdFreeBSD5192E7CA-7D4F-11D9-A9E7-0001020EED82
HistoryJan 30, 2005 - 12:00 a.m.

mod_python -- information leakage vulnerability

2005-01-3000:00:00
vuxml.freebsd.org
15

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.003 Low

EPSS

Percentile

70.6%

Mark J Cox reports:

Graham Dumpleton discovered a flaw which can affect
anyone using the publisher handle of the Apache Software
Foundation mod_python. The publisher handle lets you
publish objects inside modules to make them callable via
URL. The flaw allows a carefully crafted URL to obtain
extra information that should not be visible (information
leak).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchmod_python< 2.7.11UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.003 Low

EPSS

Percentile

70.6%