Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-0772

Опубликовано: 02 сент. 2016
Источник: debian
EPSS Низкий

Описание

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.5fixed3.5.2~rc1-1package
python3.4removedpackage
python3.2removedpackage
python2.7fixed2.7.12~rc1-1package
python2.7fixed2.7.9-2+deb8u1jessiepackage

Примечания

  • 3.4 branch: https://hg.python.org/cpython/rev/d590114c2394

  • 2.7 branch: https://hg.python.org/cpython/rev/b3ce713fb9be

EPSS

Процентиль: 90%
0.05947
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 4.8
redhat
больше 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
nvd
больше 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
github
больше 3 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

suse-cvrf
больше 9 лет назад

Security update for python

EPSS

Процентиль: 90%
0.05947
Низкий