A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://python-security.readthedocs.io/vuln/http-header-injection.html below:

HTTP header injection — Python Security 0.0 documentation

HTTP header injection

HTTP header injection in urllib, urrlib2, httplib and http.client modules.

CRLF injection vulnerability in the HTTPConnection.putheader() function in urllib2 and urllib in CPython before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

Reported again in January 2016 by Timothy D. Morgan (Blindspot Security), with a full disclosed at 2016-06-15.

Dates:

Fixed In Python issue

HTTP header injection in urrlib2/urllib/httplib/http.client (CVE-2016-5699).

CVE-2016-5699

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

Timeline

Timeline using the disclosure date 2014-11-24 as reference:

Links

RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4