CVE-2024-6923
MEDIUM5.5EPSS 0.24%Email header injection due to unquoted newlines
Published: 8/1/2024Modified: 12/3/2025
Also known as:ALPINE-CVE-2024-6923
Description
There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
Affected packages (9)
- Alpine/python3from 0, < 3.10.15-r0
- Bitnami/libpythonfrom 0, < 3.8.20, >= 3.9.0, < 3.9.20, >= 3.10.0, < 3.10.15, >= 3.11.0, < 3.11.10, >= 3.12.0, < 3.12.5
- Bitnami/pythonfrom 0, < 3.8.20, >= 3.9.0, < 3.9.20, >= 3.10.0, < 3.10.15, >= 3.11.0, < 3.11.10, >= 3.12.0, < 3.12.5
- Bitnami/python-minfrom 0, < 3.8.20, >= 3.9.0, < 3.9.20, >= 3.10.0, < 3.10.15, >= 3.11.0, < 3.11.10, >= 3.12.0, < 3.12.5
- Debian/pypy3from 0, < 7.3.5+dfsg-2+deb11u5
- Debian/python2.7from 0
- Debian/python3.11from 0, < 3.11.2-6+deb12u5
- Debian/python3.13from 0, < 3.13.0~rc2-1
- Debian/python3.9from 0, < 3.9.2-1+deb11u2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
References (18)
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2024-6923
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2024-6923
- WEBhttps://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147
- WEBhttps://github.com/python/cpython/commit/097633981879b3c9de9a1dd120d3aa585ecc2384
- WEBhttps://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7
- WEBhttps://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0
- WEBhttps://github.com/python/cpython/commit/b158a76ce094897c870fb6b3de62887b7ccc33f1
- WEBhttps://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6
- WEBhttps://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533
- WEBhttps://github.com/python/cpython/issues/121650
- WEBhttps://github.com/python/cpython/pull/122233
- WEBhttps://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
- WEBhttps://lists.debian.org/debian-lts-announce/2025/01/msg00005.html
- WEBhttps://mail.python.org/archives/list/[email protected]/thread/QH3BUOE2DYQBWP7NAQ7UNHPPOELKISRW/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2024-6923
- WEBhttps://security.netapp.com/advisory/ntap-20240926-0003/
- WEBhttp://www.openwall.com/lists/oss-security/2024/08/01/3
- WEBhttp://www.openwall.com/lists/oss-security/2024/08/02/2