CVE-2025-1795
Public on 2025-02-28
Modified on 2025-03-04
Description
During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 2 - Core | python | Pending Fix | ||
HAQM Linux 1 | python26 | No Fix Planned | ||
HAQM Linux 1 | python27 | No Fix Planned | ||
HAQM Linux 2 - Core | python3 | 2025-03-26 | ALAS2-2025-2808 | Fixed |
HAQM Linux 2023 | python3.11 | 2025-02-26 | ALAS2023-2025-871 | Fixed |
HAQM Linux 2023 | python3.12 | Not Affected | ||
HAQM Linux 2023 | python3.9 | 2025-03-26 | ALAS2023-2025-917 | Fixed |
HAQM Linux 1 | python34 | No Fix Planned | ||
HAQM Linux 1 | python35 | No Fix Planned | ||
HAQM Linux 1 | python36 | No Fix Planned |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |