Skip to content

Directory traversal attack for CGIHTTPRequestHandler #63634

@AlexanderKruppa

Description

@AlexanderKruppa
BPO 19435
Nosy @warsaw, @birkenfeld, @vstinner, @larryhastings, @tiran, @benjaminp, @ned-deily, @Janzert
Files
  • cgi.patch
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = 'https://github.com/tiran'
    closed_at = <Date 2013-10-30.16:51:29.356>
    created_at = <Date 2013-10-29.16:34:01.527>
    labels = ['type-security', 'library', 'release-blocker']
    title = 'Directory traversal attack for CGIHTTPRequestHandler'
    updated_at = <Date 2014-07-13.05:34:43.791>
    user = 'https://bugs.python.org/AlexanderKruppa'

    bugs.python.org fields:

    activity = <Date 2014-07-13.05:34:43.791>
    actor = 'ned.deily'
    assignee = 'christian.heimes'
    closed = True
    closed_date = <Date 2013-10-30.16:51:29.356>
    closer = 'python-dev'
    components = ['Library (Lib)']
    creation = <Date 2013-10-29.16:34:01.527>
    creator = 'Alexander.Kruppa'
    dependencies = []
    files = ['32413']
    hgrepos = []
    issue_num = 19435
    keywords = ['patch']
    message_count = 6.0
    messages = ['201645', '201647', '201673', '201747', '222911', '222913']
    nosy_count = 12.0
    nosy_names = ['barry', 'georg.brandl', 'vstinner', 'larry', 'christian.heimes', 'benjamin.peterson', 'ned.deily', 'Arfrever', 'python-dev', 'janzert', 'Alexander.Kruppa', 'glondu']
    pr_nums = []
    priority = 'release blocker'
    resolution = 'fixed'
    stage = 'resolved'
    status = 'closed'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue19435'
    versions = ['Python 2.7', 'Python 3.2', 'Python 3.3', 'Python 3.4']

    Metadata

    Metadata

    Assignees

    Labels

    release-blockerstdlibStandard Library Python modules in the Lib/ directorytype-securityA security issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions