CVE-2015-20107

Updated: 2026-02-20 04:38:49.008646

Description:

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x HIGH 8.0
CVSS Version 3.x HIGH 7.6

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Ubuntu 20.04 python 2.7 7.6 HIGH In Testing 2026-02-20 19:11:23
Ubuntu 20.04 python 3.6 7.6 HIGH In Testing 2026-02-20 19:11:28
Ubuntu 22.04 python 2.7 7.6 HIGH In Testing 2026-02-20 19:11:23
Ubuntu 22.04 python 3.6 7.6 HIGH In Testing 2026-02-20 19:11:27
Ubuntu 24.04 python 2.7 7.6 HIGH In Testing 2026-02-20 19:11:22
Ubuntu 24.04 python 3.6 7.6 HIGH In Testing 2026-02-20 19:11:26
Total: 36