OS Command Injection In python3
Description
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
alpine v3.22 | =3.1.3-r0 || =3.10.0-r0 || =3.10.0-r1 || =3.10.1-r0 || =3.10.2-r0 || =3.10.2-r1 || =3.10.3-r0 || =3.10.3-r1 || =3.10.4-r0 || =3.2.0-r0 || =3.2.3-r0 || =3.3.0-r0 || =3.3.2-r0 || =3.3.3-r0 || =3.3.4-r0 || =3.4.1-r0 || =3.4.2-r0 || =3.4.2-r1 || =3.4.3-r1 || =3.4.3-r2 || =3.5.0-r0 || =3.5.1-r0 || =3.5.1-r1 || =3.5.1-r2 || =3.5.1-r3 || =3.5.2-r0 || =3.5.2-r1 || =3.5.2-r10 || =3.5.2-r2 || =3.5.2-r3 || =3.5.2-r4 || =3.5.2-r5 || =3.5.2-r6 || =3.5.2-r7 || =3.5.2-r8 || =3.5.2-r9 || =3.6.0-r0 || =3.6.1-r0 || =3.6.1-r1 || =3.6.1-r2 || =3.6.1-r3 || =3.6.1-r4 || =3.6.2-r0 || =3.6.2-r1 || =3.6.2-r2 || =3.6.2-r3 || =3.6.3-r3 || =3.6.3-r4 || =3.6.3-r5 || =3.6.3-r6 || =3.6.3-r7 || =3.6.3-r8 || =3.6.3-r9 || =3.6.4-r0 || =3.6.4-r1 || =3.6.6-r0 || =3.6.6-r1 || =3.6.6-r2 || =3.6.6-r3 || =3.6.7-r0 || =3.6.8-r0 || =3.6.8-r1 || =3.6.8-r2 || =3.7.2-r0 || =3.7.3-r0 || =3.7.3-r1 || =3.7.4-r0 || =3.7.5-r0 || =3.7.5-r1 || =3.8.0-r0 || =3.8.1-r0 || =3.8.1-r1 || =3.8.1-r2 || =3.8.1-r3 || =3.8.2-r0 || =3.8.2-r1 || =3.8.2-r2 || =3.8.2-r3 || =3.8.2-r4 || =3.8.2-r5 || =3.8.2-r6 || =3.8.2-r7 || =3.8.3-r0 || =3.8.4-r0 || =3.8.5-r0 || =3.8.5-r1 || =3.8.5-r2 || =3.8.6-r0 || =3.8.7-r0 || =3.8.7-r1 || =3.8.7-r2 || =3.8.7-r3 || =3.8.8-r0 || =3.9.1-r0 || =3.9.2-r0 || =3.9.4-r0 || =3.9.5-r0 || =3.9.5-r1 || =3.9.6-r0 || =3.9.6-r1 || =3.9.6-r2 || =3.9.7-r2 || =3.9.7-r3 || =3.9.7-r4 || >=0 <3.10.5-r0 | 3.10.5-r0 | |
alpine v3.17 | =3.1.3-r0 || =3.10.0-r0 || =3.10.0-r1 || =3.10.1-r0 || =3.10.2-r0 || =3.10.2-r1 || =3.10.3-r0 || =3.10.3-r1 || =3.10.4-r0 || =3.2.0-r0 || =3.2.3-r0 || =3.3.0-r0 || =3.3.2-r0 || =3.3.3-r0 || =3.3.4-r0 || =3.4.1-r0 || =3.4.2-r0 || =3.4.2-r1 || =3.4.3-r1 || =3.4.3-r2 || =3.5.0-r0 || =3.5.1-r0 || =3.5.1-r1 || =3.5.1-r2 || =3.5.1-r3 || =3.5.2-r0 || =3.5.2-r1 || =3.5.2-r10 || =3.5.2-r2 || =3.5.2-r3 || =3.5.2-r4 || =3.5.2-r5 || =3.5.2-r6 || =3.5.2-r7 || =3.5.2-r8 || =3.5.2-r9 || =3.6.0-r0 || =3.6.1-r0 || =3.6.1-r1 || =3.6.1-r2 || =3.6.1-r3 || =3.6.1-r4 || =3.6.2-r0 || =3.6.2-r1 || =3.6.2-r2 || =3.6.2-r3 || =3.6.3-r3 || =3.6.3-r4 || =3.6.3-r5 || =3.6.3-r6 || =3.6.3-r7 || =3.6.3-r8 || =3.6.3-r9 || =3.6.4-r0 || =3.6.4-r1 || =3.6.6-r0 || =3.6.6-r1 || =3.6.6-r2 || =3.6.6-r3 || =3.6.7-r0 || =3.6.8-r0 || =3.6.8-r1 || =3.6.8-r2 || =3.7.2-r0 || =3.7.3-r0 || =3.7.3-r1 || =3.7.4-r0 || =3.7.5-r0 || =3.7.5-r1 || =3.8.0-r0 || =3.8.1-r0 || =3.8.1-r1 || =3.8.1-r2 || =3.8.1-r3 || =3.8.2-r0 || =3.8.2-r1 || =3.8.2-r2 || =3.8.2-r3 || =3.8.2-r4 || =3.8.2-r5 || =3.8.2-r6 || =3.8.2-r7 || =3.8.3-r0 || =3.8.4-r0 || =3.8.5-r0 || =3.8.5-r1 || =3.8.5-r2 || =3.8.6-r0 || =3.8.7-r0 || =3.8.7-r1 || =3.8.7-r2 || =3.8.7-r3 || =3.8.8-r0 || =3.9.1-r0 || =3.9.2-r0 || =3.9.4-r0 || =3.9.5-r0 || =3.9.5-r1 || =3.9.6-r0 || =3.9.6-r1 || =3.9.6-r2 || =3.9.7-r2 || =3.9.7-r3 || =3.9.7-r4 || >=0 <3.10.5-r0 | 3.10.5-r0 | |
alpine v3.18 | =3.1.3-r0 || =3.10.0-r0 || =3.10.0-r1 || =3.10.1-r0 || =3.10.2-r0 || =3.10.2-r1 || =3.10.3-r0 || =3.10.3-r1 || =3.10.4-r0 || =3.2.0-r0 || =3.2.3-r0 || =3.3.0-r0 || =3.3.2-r0 || =3.3.3-r0 || =3.3.4-r0 || =3.4.1-r0 || =3.4.2-r0 || =3.4.2-r1 || =3.4.3-r1 || =3.4.3-r2 || =3.5.0-r0 || =3.5.1-r0 || =3.5.1-r1 || =3.5.1-r2 || =3.5.1-r3 || =3.5.2-r0 || =3.5.2-r1 || =3.5.2-r10 || =3.5.2-r2 || =3.5.2-r3 || =3.5.2-r4 || =3.5.2-r5 || =3.5.2-r6 || =3.5.2-r7 || =3.5.2-r8 || =3.5.2-r9 || =3.6.0-r0 || =3.6.1-r0 || =3.6.1-r1 || =3.6.1-r2 || =3.6.1-r3 || =3.6.1-r4 || =3.6.2-r0 || =3.6.2-r1 || =3.6.2-r2 || =3.6.2-r3 || =3.6.3-r3 || =3.6.3-r4 || =3.6.3-r5 || =3.6.3-r6 || =3.6.3-r7 || =3.6.3-r8 || =3.6.3-r9 || =3.6.4-r0 || =3.6.4-r1 || =3.6.6-r0 || =3.6.6-r1 || =3.6.6-r2 || =3.6.6-r3 || =3.6.7-r0 || =3.6.8-r0 || =3.6.8-r1 || =3.6.8-r2 || =3.7.2-r0 || =3.7.3-r0 || =3.7.3-r1 || =3.7.4-r0 || =3.7.5-r0 || =3.7.5-r1 || =3.8.0-r0 || =3.8.1-r0 || =3.8.1-r1 || =3.8.1-r2 || =3.8.1-r3 || =3.8.2-r0 || =3.8.2-r1 || =3.8.2-r2 || =3.8.2-r3 || =3.8.2-r4 || =3.8.2-r5 || =3.8.2-r6 || =3.8.2-r7 || =3.8.3-r0 || =3.8.4-r0 || =3.8.5-r0 || =3.8.5-r1 || =3.8.5-r2 || =3.8.6-r0 || =3.8.7-r0 || =3.8.7-r1 || =3.8.7-r2 || =3.8.7-r3 || =3.8.8-r0 || =3.9.1-r0 || =3.9.2-r0 || =3.9.4-r0 || =3.9.5-r0 || =3.9.5-r1 || =3.9.6-r0 || =3.9.6-r1 || =3.9.6-r2 || =3.9.7-r2 || =3.9.7-r3 || =3.9.7-r4 || >=0 <3.10.5-r0 | 3.10.5-r0 | |
alpine v3.20 | =3.1.3-r0 || =3.10.0-r0 || =3.10.0-r1 || =3.10.1-r0 || =3.10.2-r0 || =3.10.2-r1 || =3.10.3-r0 || =3.10.3-r1 || =3.10.4-r0 || =3.2.0-r0 || =3.2.3-r0 || =3.3.0-r0 || =3.3.2-r0 || =3.3.3-r0 || =3.3.4-r0 || =3.4.1-r0 || =3.4.2-r0 || =3.4.2-r1 || =3.4.3-r1 || =3.4.3-r2 || =3.5.0-r0 || =3.5.1-r0 || =3.5.1-r1 || =3.5.1-r2 || =3.5.1-r3 || =3.5.2-r0 || =3.5.2-r1 || =3.5.2-r10 || =3.5.2-r2 || =3.5.2-r3 || =3.5.2-r4 || =3.5.2-r5 || =3.5.2-r6 || =3.5.2-r7 || =3.5.2-r8 || =3.5.2-r9 || =3.6.0-r0 || =3.6.1-r0 || =3.6.1-r1 || =3.6.1-r2 || =3.6.1-r3 || =3.6.1-r4 || =3.6.2-r0 || =3.6.2-r1 || =3.6.2-r2 || =3.6.2-r3 || =3.6.3-r3 || =3.6.3-r4 || =3.6.3-r5 || =3.6.3-r6 || =3.6.3-r7 || =3.6.3-r8 || =3.6.3-r9 || =3.6.4-r0 || =3.6.4-r1 || =3.6.6-r0 || =3.6.6-r1 || =3.6.6-r2 || =3.6.6-r3 || =3.6.7-r0 || =3.6.8-r0 || =3.6.8-r1 || =3.6.8-r2 || =3.7.2-r0 || =3.7.3-r0 || =3.7.3-r1 || =3.7.4-r0 || =3.7.5-r0 || =3.7.5-r1 || =3.8.0-r0 || =3.8.1-r0 || =3.8.1-r1 || =3.8.1-r2 || =3.8.1-r3 || =3.8.2-r0 || =3.8.2-r1 || =3.8.2-r2 || =3.8.2-r3 || =3.8.2-r4 || =3.8.2-r5 || =3.8.2-r6 || =3.8.2-r7 || =3.8.3-r0 || =3.8.4-r0 || =3.8.5-r0 || =3.8.5-r1 || =3.8.5-r2 || =3.8.6-r0 || =3.8.7-r0 || =3.8.7-r1 || =3.8.7-r2 || =3.8.7-r3 || =3.8.8-r0 || =3.9.1-r0 || =3.9.2-r0 || =3.9.4-r0 || =3.9.5-r0 || =3.9.5-r1 || =3.9.6-r0 || =3.9.6-r1 || =3.9.6-r2 || =3.9.7-r2 || =3.9.7-r3 || =3.9.7-r4 || >=0 <3.10.5-r0 | 3.10.5-r0 | |
alpine v3.21 | =3.1.3-r0 || =3.10.0-r0 || =3.10.0-r1 || =3.10.1-r0 || =3.10.2-r0 || =3.10.2-r1 || =3.10.3-r0 || =3.10.3-r1 || =3.10.4-r0 || =3.2.0-r0 || =3.2.3-r0 || =3.3.0-r0 || =3.3.2-r0 || =3.3.3-r0 || =3.3.4-r0 || =3.4.1-r0 || =3.4.2-r0 || =3.4.2-r1 || =3.4.3-r1 || =3.4.3-r2 || =3.5.0-r0 || =3.5.1-r0 || =3.5.1-r1 || =3.5.1-r2 || =3.5.1-r3 || =3.5.2-r0 || =3.5.2-r1 || =3.5.2-r10 || =3.5.2-r2 || =3.5.2-r3 || =3.5.2-r4 || =3.5.2-r5 || =3.5.2-r6 || =3.5.2-r7 || =3.5.2-r8 || =3.5.2-r9 || =3.6.0-r0 || =3.6.1-r0 || =3.6.1-r1 || =3.6.1-r2 || =3.6.1-r3 || =3.6.1-r4 || =3.6.2-r0 || =3.6.2-r1 || =3.6.2-r2 || =3.6.2-r3 || =3.6.3-r3 || =3.6.3-r4 || =3.6.3-r5 || =3.6.3-r6 || =3.6.3-r7 || =3.6.3-r8 || =3.6.3-r9 || =3.6.4-r0 || =3.6.4-r1 || =3.6.6-r0 || =3.6.6-r1 || =3.6.6-r2 || =3.6.6-r3 || =3.6.7-r0 || =3.6.8-r0 || =3.6.8-r1 || =3.6.8-r2 || =3.7.2-r0 || =3.7.3-r0 || =3.7.3-r1 || =3.7.4-r0 || =3.7.5-r0 || =3.7.5-r1 || =3.8.0-r0 || =3.8.1-r0 || =3.8.1-r1 || =3.8.1-r2 || =3.8.1-r3 || =3.8.2-r0 || =3.8.2-r1 || =3.8.2-r2 || =3.8.2-r3 || =3.8.2-r4 || =3.8.2-r5 || =3.8.2-r6 || =3.8.2-r7 || =3.8.3-r0 || =3.8.4-r0 || =3.8.5-r0 || =3.8.5-r1 || =3.8.5-r2 || =3.8.6-r0 || =3.8.7-r0 || =3.8.7-r1 || =3.8.7-r2 || =3.8.7-r3 || =3.8.8-r0 || =3.9.1-r0 || =3.9.2-r0 || =3.9.4-r0 || =3.9.5-r0 || =3.9.5-r1 || =3.9.6-r0 || =3.9.6-r1 || =3.9.6-r2 || =3.9.7-r2 || =3.9.7-r3 || =3.9.7-r4 || >=0 <3.10.5-r0 | 3.10.5-r0 | |
debian 11 | =7.3.10+dfsg-1 || =7.3.10~rc3+dfsg-1 || =7.3.10~rc3+dfsg-2 || =7.3.11+dfsg-1 || =7.3.11+dfsg-2 || =7.3.12+dfsg-1 || =7.3.12~rc1+dfsg-1 || =7.3.12~rc2+dfsg-1 || =7.3.13+dfsg-1 || =7.3.14+dfsg-1 || =7.3.15+dfsg-1 || =7.3.16+dfsg-1 || =7.3.16+dfsg-2 || =7.3.17+dfsg-1 || =7.3.17+dfsg-2 || =7.3.17+dfsg-3 || =7.3.18+dfsg-1 || =7.3.18+dfsg-2 || =7.3.19+dfsg-1 || =7.3.19+dfsg-2 || =7.3.20+dfsg-1 || =7.3.20+dfsg-2 || =7.3.20+dfsg-3 || =7.3.20+dfsg-4 || =7.3.21+dfsg-1 || =7.3.21+dfsg-2 || =7.3.21+dfsg-3 || =7.3.21+dfsg-4 || =7.3.5+dfsg-2 || =7.3.5+dfsg-2+deb11u1 || =7.3.5+dfsg-2+deb11u2 || =7.3.5+dfsg-2+deb11u3 || =7.3.5+dfsg-2+deb11u4 || =7.3.5+dfsg-2+deb11u5 || =7.3.6+dfsg-1 || =7.3.6~rc2+dfsg-1 || =7.3.6~rc2+dfsg-2 || =7.3.7+dfsg-1 || =7.3.7+dfsg-2 || =7.3.7+dfsg-3 || =7.3.7+dfsg-4 || =7.3.7+dfsg-5 || =7.3.8+dfsg-1 || =7.3.8+dfsg-2 || =7.3.8~rc1+dfsg-1 || =7.3.8~rc1+dfsg-2 || =7.3.9+dfsg-1 || =7.3.9+dfsg-2 || =7.3.9+dfsg-3 || =7.3.9+dfsg-4 || =7.3.9+dfsg-5 | - | |
debian 12 | >=0 <7.3.11+dfsg-1 | 7.3.11+dfsg-1 | |
debian 13 | >=0 <7.3.11+dfsg-1 | 7.3.11+dfsg-1 | |
debian 14 | >=0 <7.3.11+dfsg-1 | 7.3.11+dfsg-1 | |
debian 11 | =2.7.18-10 || =2.7.18-11 || =2.7.18-12 || =2.7.18-13 || =2.7.18-13.1 || =2.7.18-13.1~exp1 || =2.7.18-13.2 || =2.7.18-8 || =2.7.18-8+deb11u1 || =2.7.18-9 | - |
1-10 of 20
10
Aliases
References
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.