Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2023-36632

CVE-2023-36632, sévérité high (CVSS 7.5) : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
7.5

Échelle NVD

Exploitation
1.6 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0

EN The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data that was supposed to contain a name and an e-mail address. NOTE: email.utils.parseaddr is categorized as a Legacy API in the documentation of the Python email package. Applications should instead use the email.parser.BytesParser or email.parser.Parser class. NOTE: the vendor's perspective is that this is neither a vulnerability nor a bug. The email package is intended to have size limits and to throw an exception when limits are exceeded; they were exceeded by the example demonstration code.

Vecteur d'attaque : Réseau Aucun privilège requis Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS 1.58% au-dessus de la médiane percentile 74.1%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Python 3.12 Windows winget:Python.Python.3.12
    Affecté ≤3.11.4 Corrigé > 3.11.4 Dernière suivie 3.12.10 patchée
  • Python 3.13 Windows winget:Python.Python.3.13
    Affecté ≤3.11.4 Corrigé > 3.11.4 Dernière suivie 3.13.15 patchée
  • Python 3.14 Windows winget:Python.Python.3.14
    Affecté ≤3.11.4 Corrigé > 3.11.4 Dernière suivie 3.14.7 patchée
Configurations CPE vulnérables (1)
Vendor Produit Versions
python python
Toutes plateformes (wildcard)
≤3.11.4
Voir sur NVD ↗