Back

HIGH

python: Command injection in Lib/webbrowser.py

Published Dec 14, 2017

Description

Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting

Affected products

Remediation

Red Hat statement

As per upstream, "exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting". On testing it seems, upstream has correctly concluded the non-security nature of this bug.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 14, 2017
Updated Aug 5, 2024
Reserved Dec 11, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 14, 2017