Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7440

Опубликовано: 07 июн. 2016
Источник: debian
EPSS Низкий

Описание

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.4fixed3.4~b1-4package
python3.3fixed3.3.3-1package
python3.2removedpackage
python3.2no-dsawheezypackage
python3.1removedpackage
python3.1no-dsasqueezepackage
python2.7fixed2.7.9-1package
python2.7no-dsawheezypackage
python2.6removedpackage
python2.6no-dsawheezypackage
python2.6no-dsasqueezepackage
python2.5removedpackage
python2.5no-dsasqueezepackage

Примечания

  • https://bugs.python.org/issue17997#msg194950

  • https://hg.python.org/cpython/rev/10d0edadbcdd

  • The CVE is only about refusing multiple wildcards. Backporting that part only is not so difficult.

EPSS

Процентиль: 67%
0.00557
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 9 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

redhat
почти 12 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS3: 5.9
nvd
около 9 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

suse-cvrf
почти 10 лет назад

Recommended update for python-setuptools

suse-cvrf
почти 10 лет назад

Security update for python-setuptools

EPSS

Процентиль: 67%
0.00557
Низкий