Bug 2431373 (CVE-2025-15367) - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
Summary: CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
Keywords:
Status: NEW
Alias: CVE-2025-15367
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2431634 2431635 2431636 2431637 2431638 2431639 2431640 2431641 2431642 2431643 2431644 2431645 2431646 2431647 2431648 2431649 2431650 2431651 2431652 2431653 2431654 2431655 2431656
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-20 22:02 UTC by OSIDB Bzimport
Modified: 2026-01-21 14:58 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-20 22:02:34 UTC
The poplib module, when passed a user-controlled command, can have
additional commands injected using newlines. Mitigation rejects commands
containing control characters.


Note You need to log in before you can comment on or make changes to this bug.