The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3966-1 | pypy3 security update |
![]() |
DLA-3980-1 | python3.9 security update |
![]() |
DLA-4094-1 | mercurial security update |
![]() |
USN-7015-1 | Python vulnerabilities |
![]() |
USN-7015-3 | Python vulnerability |
![]() |
USN-7015-4 | Python vulnerability |
![]() |
USN-7015-7 | Python 2.7 regression |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 19 May 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fedoraproject
Fedoraproject fedora Netapp Netapp active Iq Unified Manager Netapp ontap Select Deploy Administration Utility |
|
CPEs | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
Vendors & Products |
Fedoraproject
Fedoraproject fedora Netapp Netapp active Iq Unified Manager Netapp ontap Select Deploy Administration Utility |
Fri, 22 Nov 2024 12:00:00 +0000

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T12:01:32.288Z
Reserved: 2023-02-27T00:00:00
Link: CVE-2023-27043

No data.

Status : Analyzed
Published: 2023-04-19T00:15:07.973
Modified: 2025-05-19T12:38:20.773
Link: CVE-2023-27043


No data.