python: mailcap: findmatch() function does not sanitize the second argument
Published Apr 13, 2022
7.6
HIGHCVSS 3.1
EPSS 7.07%
Description
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Affected products
No data.
Configuration 1
Configuration 2
- n/a
- n/a
- n/a
- n/a
Configuration 3
- 35
- 36
- 37
No data.
Red Hat Enterprise Linux 8
python27:2.7-8070020220617114255.056aacbc
Fixed · RHSA-2022:7593
Red Hat Enterprise Linux 8
python3-0:3.6.8-47.el8_6
Fixed · RHSA-2022:6457
Red Hat Enterprise Linux 8
python3-0:3.6.8-47.el8_6
Fixed · RHSA-2022:6457
Red Hat Enterprise Linux 8
python38-devel:3.8-8070020220916150349.bd194b04
Fixed · RHSA-2022:7581
Red Hat Enterprise Linux 8
python38:3.8-8070020220916150349.bd194b04
Fixed · RHSA-2022:7581
Red Hat Enterprise Linux 8
python39-devel:3.9-8070020220916150556.be1f0497
Fixed · RHSA-2022:7592
Red Hat Enterprise Linux 8
python39:3.9-8070020220916150556.be1f0497
Fixed · RHSA-2022:7592
Red Hat Enterprise Linux 9
python3.9-0:3.9.14-1.el9
Fixed · RHSA-2022:8353
Red Hat Enterprise Linux 9
python3.9-0:3.9.14-1.el9
Fixed · RHSA-2022:8353
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-0:3.8.14-1.el7
Fixed · RHSA-2022:6766
Red Hat Enterprise Linux 6
python
Not affected
Red Hat Enterprise Linux 7
python
Not affected
Red Hat Enterprise Linux 7
python3
Out of support scope
Red Hat Enterprise Linux 8
gimp:flatpak/python2
Not affected
Red Hat Enterprise Linux 8
inkscape:flatpak/python2
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Software Collections
python27
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python27:2.7-8070020220617114255.056aacbc | Fixed | RHSA-2022:7593 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-47.el8_6 | Fixed | RHSA-2022:6457 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-47.el8_6 | Fixed | RHSA-2022:6457 |
| Red Hat Enterprise Linux 8 | python38-devel:3.8-8070020220916150349.bd194b04 | Fixed | RHSA-2022:7581 |
| Red Hat Enterprise Linux 8 | python38:3.8-8070020220916150349.bd194b04 | Fixed | RHSA-2022:7581 |
| Red Hat Enterprise Linux 8 | python39-devel:3.9-8070020220916150556.be1f0497 | Fixed | RHSA-2022:7592 |
| Red Hat Enterprise Linux 8 | python39:3.9-8070020220916150556.be1f0497 | Fixed | RHSA-2022:7592 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.14-1.el9 | Fixed | RHSA-2022:8353 |
| Red Hat Enterprise Linux 9 | python3.9-0:3.9.14-1.el9 | Fixed | RHSA-2022:8353 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-0:3.8.14-1.el7 | Fixed | RHSA-2022:6766 |
| Red Hat Enterprise Linux 6 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | gimp:flatpak/python2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | inkscape:flatpak/python2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Software Collections | python27 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.
Red Hat mitigation
Users should upgrade to the latest version. If this is not possible and the affected version of the Python mailcap module has to be used then applications that use mailcap module should verify user input before passing it to the mailcap module, and the returned command before executing it.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:P/I:C/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 7.07% (0.07074) | 94.02th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.71% (0.06705) | 93.05th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.13% (0.01132) | 76.38th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.02% (0.09022) | 87.57th | v4 (v2025.03.14) |
| Mar 28, 2025 | 1.13% (0.01132) | 76.39th | v4 (v2025.03.14) |
| Mar 27, 2025 | 9.02% (0.09022) | 91.44th | v4 (v2025.03.14) |
| Mar 20, 2025 | 1.13% (0.01132) | 76.47th | v4 (v2025.03.14) |
| Mar 19, 2025 | 9.02% (0.09022) | 91.59th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.13% (0.01132) | 76.85th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.18% (0.00183) | 56.86th | v3 (v2023.03.01) |
| Jul 5, 2024 | 0.18% (0.00183) | 55.79th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.14% (0.00141) | 49.63th | v3 (v2023.03.01) |
| Nov 4, 2023 | 0.11% (0.00113) | 44.60th | v3 (v2023.03.01) |
| May 8, 2023 | 0.09% (0.00090) | 37.16th | v3 (v2023.03.01) |
| Mar 14, 2023 | 0.11% (0.00110) | 42.41th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00093) | 38.07th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Dec 28, 2022 | 18.26% (0.18256) | 96.22th | v2 (v2022.01.01) |
| Nov 13, 2022 | 1.55% (0.01547) | 74.51th | v2 (v2022.01.01) |
| Jun 20, 2022 | 2.69% (0.02686) | 81.58th | v2 (v2022.01.01) |
| Jun 19, 2022 | 1.54% (0.01537) | 72.90th | v2 (v2022.01.01) |
| Jun 17, 2022 | 0.95% (0.00954) | 33.52th | v2 (v2022.01.01) |
| Apr 14, 2022 | 0.89% (0.00885) | 24.40th | v2 (v2022.01.01) |
References (34)
- https://access.redhat.com/security/cve/CVE-2015-20107 Vendor Advisory
- https://bugs.python.org/issue24778 ExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2075390 Issue Tracking
- https://github.com/python/cpython/issues/68966 Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html mailing-list
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html mailing-list
- https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46KWPTI72SSEOF53DOYQBQOCN4QQB2GE/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/53TQZFLS6O3FLIMVSXFEEPZSWLDZLBOX/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/57NECACX333A3BBZM2TR2VZ4ZE3UG3SN/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DBVY4YC2P6EPZZ2DROOXHDOWZ4BJFLW/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIKVSW3H6W2GQGDE5DTIWLGFNH6KKEW/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AKGMYDVKI3XNM27B6I6RQ6QV3TVJAUCG/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ERYMM2QVDPOJLX4LYXWYIQN5FOIJLDRY/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F3LNY2NHM6J22O6Q5ANOE3SZRK3OACKR/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCIO2W4DUVVMI6L52QCC4TT2B3K5VWHS/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FIRUTX47BJD2HYJDLMI7JJBVCYFAPKAQ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GPCLGZZJPVXFWUWVV5WCD5FNUAFLKBDN/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HAI2GBC7WKH7J5NH6J2IW5RT3VF2SF5M/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KAY6VBNVEFUXKJF37WFHYXUSRDEK34N3/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYG3EMFR7ZHC46TDNM7SNWO64A3W7EUF/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONXSGLASNLGFL57YU6WT6Y5YURSFV43U/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTTZGLD2YBMMG6U6F5HOTPOGGPBIURMA/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIOJUZ5JMEMGSKNISTOVI4PDP36FDL5Y/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5664BGZVTA46LQDNTYX5THG6CN4FYJX/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO2H6CKWLRGTTZCGUQVELW6LUH437Q3O/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4E2WBEJ42CGLGDHD6ZXOLZ2W6G3YOVD/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-20107
- https://python-security.readthedocs.io/vuln/mailcap-shell-injection.html PatchThird Party Advisory
- https://security.gentoo.org/glsa/202305-02 vendor-advisory
- https://security.netapp.com/advisory/ntap-20220616-0001/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2015-20107
Change history (0)
No recorded changes yet.