Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2011-1521

The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.

  • Published: May 25, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2011-1521
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.4
  • AV:N/AC:L/Au:N/C:P/I:N/A:P

CWEs:

Software From Fixed in
python / python 2.4.2 2.4.2.x
python / python 2.5.1 2.5.1.x
python / python 2.3.4 2.3.4.x
python / python 2.6.6 2.6.6.x
python / python 2.1 2.1.x
python / python 2.0.1 2.0.1.x
python / python 2.6.1 2.6.1.x
python / python 2.3.1 2.3.1.x
python / python 2.1.2 2.1.2.x
python / python 2.2.1 2.2.1.x
python / python 2.5.4 2.5.4.x
python / python 2.2.2 2.2.2.x
python / python 2.1.1 2.1.1.x
python / python 2.3.3 2.3.3.x
python / python 2.7.1 2.7.1.x
python / python 2.3.2 2.3.2.x
python / python 2.6.7 2.6.7.x
python / python 2.4.6 2.4.6.x
python / python 2.0 2.0.x
python / python 2.2.3 2.2.3.x
python / python 2.5.2 2.5.2.x
python / python 2.3.7 2.3.7.x
python / python 2.6.4 2.6.4.x
python / python 2.5.3 2.5.3.x
python / python 2.4.4 2.4.4.x
python / python 2.2 2.2.x
python / python 2.3.5 2.3.5.x
python / python 2.1.3 2.1.3.x
python / python 2.4.1 2.4.1.x
python / python 2.4.3 2.4.3.x
python / python 2.6.5 2.6.5.x
python / python 3.1 3.1.x
python / python 3.1.1 3.1.1.x
python / python 3.0 3.0.x
python / python 3.0.1 3.0.1.x
python / python 3.1.2 3.1.2.x
python / python 3.2 3.2.x
python / python 3.2-alpha 3.2-alpha.x
python / python 3.1.3 3.1.3.x