Bug 2196183 (CVE-2023-27043)

Summary: CVE-2023-27043 python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple
Product: [Other] Security Response Reporter: Sandipan Roy <saroy>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: cstratak, hhorak, jorton, lbalhar, python-maint
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2196185, 2196186, 2196187, 2196188, 2196190, 2196191, 2196192, 2196193, 2196194, 2196204, 2196209, 2196210, 2196211, 2196212, 2196184, 2196200, 2196201, 2196202, 2196203, 2196205, 2196206, 2196207, 2196208    
Bug Blocks: 2193413    

Description Sandipan Roy 2023-05-08 09:20:38 UTC
The e-mail module of Python 0 - 2.7.18, 3.x - 3.11 incorrectly parses e-mail addresses which contain a special character. This vulnerability allows attackers to send messages from e-ail addresses that would otherwise be rejected.

https://github.com/python/cpython/issues/102988
http://python.org

Comment 1 Sandipan Roy 2023-05-08 09:24:15 UTC
Created mingw-python3 tracking bugs for this issue:

Affects: fedora-all [bug 2196185]


Created python2.7 tracking bugs for this issue:

Affects: fedora-all [bug 2196186]


Created python3.10 tracking bugs for this issue:

Affects: fedora-all [bug 2196187]


Created python3.11 tracking bugs for this issue:

Affects: fedora-all [bug 2196188]


Created python3.12 tracking bugs for this issue:

Affects: fedora-all [bug 2196190]


Created python3.6 tracking bugs for this issue:

Affects: fedora-all [bug 2196191]


Created python3.7 tracking bugs for this issue:

Affects: fedora-all [bug 2196192]


Created python3.8 tracking bugs for this issue:

Affects: fedora-all [bug 2196193]


Created python3.9 tracking bugs for this issue:

Affects: fedora-all [bug 2196194]


Created python34 tracking bugs for this issue:

Affects: epel-7 [bug 2196184]

Comment 2 Sandipan Roy 2023-05-08 09:24:58 UTC
https://github.com/advisories/GHSA-5mwm-wccq-xqcp