CVE-2015-20107: Fedoraproject Fedora
High severity, CVSS 7.6. EPSS: 2.8% chance of exploitation in the next 30 days.
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Affected products
- Fedoraproject Fedora: version 35 only; version 36 only; version 37 only
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Python Python: from 3.7.0, up to and including 3.7.15; from 3.8.0, up to and including 3.8.15; from 3.9.0, up to and including 3.9.15; from 3.10.0, before 3.10.8 (fixed in 3.10.8)
Published 2022-04-13. Last modified 2026-10-08.