Bug 2196183 (CVE-2023-27043)

Summary: CVE-2023-27043 python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple
Product: [Other] Security Response Reporter: Sandipan Roy <saroy>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: cstratak, gsuckevi, hhorak, jorton, lbalhar, lmlikith, python-maint, sbalasub
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2196184, 2196185, 2196186, 2196187, 2196188, 2196190, 2196191, 2196192, 2196193, 2196194, 2196200, 2196201, 2196202, 2196203, 2196204, 2196205, 2196206, 2196207, 2196208, 2196209, 2196210, 2196211, 2196212    
Bug Blocks: 2193413    

Description Sandipan Roy 2023-05-08 09:20:38 UTC
The e-mail module of Python 0 - 2.7.18, 3.x - 3.11 incorrectly parses e-mail addresses which contain a special character. This vulnerability allows attackers to send messages from e-ail addresses that would otherwise be rejected.

https://github.com/python/cpython/issues/102988
http://python.org

Comment 1 Sandipan Roy 2023-05-08 09:24:15 UTC
Created mingw-python3 tracking bugs for this issue:

Affects: fedora-all [bug 2196185]


Created python2.7 tracking bugs for this issue:

Affects: fedora-all [bug 2196186]


Created python3.10 tracking bugs for this issue:

Affects: fedora-all [bug 2196187]


Created python3.11 tracking bugs for this issue:

Affects: fedora-all [bug 2196188]


Created python3.12 tracking bugs for this issue:

Affects: fedora-all [bug 2196190]


Created python3.6 tracking bugs for this issue:

Affects: fedora-all [bug 2196191]


Created python3.7 tracking bugs for this issue:

Affects: fedora-all [bug 2196192]


Created python3.8 tracking bugs for this issue:

Affects: fedora-all [bug 2196193]


Created python3.9 tracking bugs for this issue:

Affects: fedora-all [bug 2196194]


Created python34 tracking bugs for this issue:

Affects: epel-7 [bug 2196184]

Comment 2 Sandipan Roy 2023-05-08 09:24:58 UTC
https://github.com/advisories/GHSA-5mwm-wccq-xqcp

Comment 9 Lumír Balhar 2023-09-20 14:13:19 UTC
We have investigated the problem in the original patch that was reverted and proposed a solution. There is a new PR addressing this but it's progressing slowly. We are closely monitoring it. https://github.com/python/cpython/pull/108250

The previously merged and then reverted patch demonstrates that we should be very careful with fixes like this.

Comment 10 Fedora Update System 2023-12-26 01:45:45 UTC
FEDORA-2023-87771f4249 has been pushed to the Fedora 39 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 11 Fedora Update System 2023-12-28 00:53:24 UTC
FEDORA-2023-c0bf8c0c4e has been pushed to the Fedora 38 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 12 errata-xmlrpc 2024-01-15 16:03:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:0256 https://access.redhat.com/errata/RHSA-2024:0256

Comment 13 errata-xmlrpc 2024-01-24 16:31:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:0466 https://access.redhat.com/errata/RHSA-2024:0466

Comment 14 errata-xmlrpc 2024-01-24 16:40:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:0454 https://access.redhat.com/errata/RHSA-2024:0454

Comment 15 errata-xmlrpc 2024-01-24 16:49:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2024:0430 https://access.redhat.com/errata/RHSA-2024:0430

Comment 16 errata-xmlrpc 2024-01-30 13:25:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:0586 https://access.redhat.com/errata/RHSA-2024:0586

Comment 19 errata-xmlrpc 2024-04-30 10:02:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:2292 https://access.redhat.com/errata/RHSA-2024:2292

Comment 20 errata-xmlrpc 2024-05-22 09:26:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:2985 https://access.redhat.com/errata/RHSA-2024:2985

Comment 21 errata-xmlrpc 2024-05-22 09:43:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:3062 https://access.redhat.com/errata/RHSA-2024:3062