Skip to content

bug #102387

@zhangxueping-zxp

Description

@zhangxueping-zxp

Bug report

Python command injection vulnerability (CVE-2015-2007)

Python version 3.10.4 and earlier has a security vulnerability, which is due to the mailcap module not adding escape characters to the commands found in the system mailcap file

Your environment

Python 3.7.9

  • CPython versions tested on:
  • Operating system and architecture:
    windows and linux

Metadata

Metadata

Assignees

No one assigned

    Labels

    type-bugAn unexpected behavior, bug, or error

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions