{"id":"CVE-2016-5699","details":"CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.","aliases":["PSF-2016-8"],"modified":"2026-08-10T03:46:42.490093906Z","published":"2016-09-02T14:59:07.003Z","related":["SUSE-SU-2016:2106-1","SUSE-SU-2016:2270-1","SUSE-SU-2016:2653-1","SUSE-SU-2016:2859-1","SUSE-SU-2019:0223-1","SUSE-SU-2020:0114-1","SUSE-SU-2020:0234-1","openSUSE-SU-2020:0086-1","openSUSE-SU-2024:10193-1","openSUSE-SU-2024:10450-1","openSUSE-SU-2024:10536-1","openSUSE-SU-2024:11284-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:python:python:3.1.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.1.0"},{"last_affected":"3.1.0"},{"introduced":"3.2.0"},{"last_affected":"3.2.0"}],"source":"CPE_STRING","vendor_product":"python:python"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/91226"},{"type":"WEB","url":"http://www.splunk.com/view/SP-CAAAPSV"},{"type":"WEB","url":"http://www.splunk.com/view/SP-CAAAPUE"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/02/msg00011.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1626.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1627.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1628.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1629.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1630.html"},{"type":"ADVISORY","url":"https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-4"},{"type":"ADVISORY","url":"https://hg.python.org/cpython/raw-file/v2.7.10/Misc/NEWS"},{"type":"FIX","url":"https://hg.python.org/cpython/rev/1c45047c5102"},{"type":"FIX","url":"https://hg.python.org/cpython/rev/bf3e1c9b80e9"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/06/14/7"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/06/15/12"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/06/16/2"},{"type":"EVIDENCE","url":"http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/python/cpython","events":[{"introduced":"0"},{"last_affected":"a5f49f5bb46b6b8c7bf1ffedbaf3009186b94b50"},{"introduced":"6046c5e0298c25515ea58abc8ab87f7413e3f743"},{"last_affected":"f5caf2b30bfe70e5107f816c9e7f7fe3ef5299d9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.7.9"},{"introduced":"3.0"},{"last_affected":"3.0"},{"introduced":"3.0.1"},{"last_affected":"3.0.1"},{"introduced":"3.1.1"},{"last_affected":"3.1.1"},{"introduced":"3.1.2"},{"last_affected":"3.1.2"},{"introduced":"3.1.3"},{"last_affected":"3.1.3"},{"introduced":"3.1.4"},{"last_affected":"3.1.4"},{"introduced":"3.1.5"},{"last_affected":"3.1.5"},{"introduced":"3.2.1"},{"last_affected":"3.2.1"},{"introduced":"3.2.2"},{"last_affected":"3.2.2"},{"introduced":"3.2.3"},{"last_affected":"3.2.3"},{"introduced":"3.2.4"},{"last_affected":"3.2.4"},{"introduced":"3.2.5"},{"last_affected":"3.2.5"},{"introduced":"3.2.6"},{"last_affected":"3.2.6"},{"introduced":"3.3.0"},{"last_affected":"3.3.0"},{"introduced":"3.3.1"},{"last_affected":"3.3.1"},{"introduced":"3.3.2"},{"last_affected":"3.3.2"},{"introduced":"3.3.3"},{"last_affected":"3.3.3"},{"introduced":"3.3.4"},{"last_affected":"3.3.4"},{"introduced":"3.3.5"},{"last_affected":"3.3.5"},{"introduced":"3.3.6"},{"last_affected":"3.3.6"},{"introduced":"3.4.0"},{"last_affected":"3.4.0"},{"introduced":"3.4.1"},{"last_affected":"3.4.1"},{"introduced":"3.4.2"},{"last_affected":"3.4.2"},{"introduced":"3.4.3"},{"last_affected":"3.4.3"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.0.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.1.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.1.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.1.4:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.1.5:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.2.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.2.4:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.2.5:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.2.6:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.3.4:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.3.5:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.3.6:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.4.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.4.2:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.4.3:*:*:*:*:*:*:*"]}}],"versions":["3.0","3.0.1","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.4.0","3.4.1","3.4.2","3.4.3","v3.4.3","v3.4.3rc1","v2.7.9","v2.7.9rc1","v3.4.2rc1","v2.7.8","v3.4.1","v3.4.1rc1","v3.4.0","v3.4.0rc3","v3.4.0rc2","v3.4.0rc1","v3.4.0b3","v3.4.0b2","v3.4.0b1","v2.7.6rc1","v3.4.0a4","v3.4.0a3","v3.4.0a2","v3.4.0a1","v2.7.5","v2.7.4rc1","v3.3.0rc3","v3.3.0rc2","v3.3.0rc1","v3.3.0b2","v3.3.0b1","v3.3.0a4","v3.3.0a3","v3.3.0a2","v2.7.3rc1","v2.7.2rc1","v2.7","v3.2rc3","v3.2rc2","v3.2rc1","v3.2b2","v3.2b1","v2.7.1","v2.7.1rc1","v3.2a4","v3.2a3","v3.2a2","v3.2a1","v2.7rc2","v2.7rc1","v2.7b2","v2.7b1","v2.7a4","v2.7a3","v2.7a2","v2.7a1","v3.1","v3.1rc2","v3.1rc1","v3.1b1","v3.1a2","v3.1a1","v3.0rc3","v3.0rc2","v2.6","v2.6rc2","v3.0rc1","v2.6rc1","v3.0b3","v2.6b3","v2.6b2","v3.0b2","v2.6b1","v3.0b1","v2.6a3","v3.0a5","v2.6a2","v3.0a4","v3.0a3","v2.6a1","v3.0a2","v3.0a1","v2.5b3","v2.5b2","v2.5b1","v2.5a2","v2.5a1","v2.5a0","v2.4","v2.4c1","v2.4b2","v2.4b1","v2.4a3","v2.4a2","v2.4a1","v2.3c2","v2.3c1","v2.2a3","v2.1","v2.1c2","v2.1c1","v2.1b2","v2.1b1","v2.1a2","v2.1a1","v2.0","v2.0c1","v2.0b2","v2.0b1","v1.6a2","v1.6a1","v1.5.2","v1.5.2c1","v1.5.2b2","v1.5.2b1","v1.5.2a2","v1.5.2a1","v1.5.1","v1.5","v1.5b2","v1.5b1","v1.5a4","v1.5a3","v1.5a2","v1.5a1","v1.4","v1.4b3","v1.4b2","v1.4b1","v1.3","v1.3b1","v1.2","v1.2b4","v1.2b3","v1.2b2","v1.2b1","v1.1.1","v1.1","v1.0.2","v1.0.1","v0.9.9","v0.9.8"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5699.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}