Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6m57-q338-h677

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

EPSS

Процентиль: 93%
0.10435
Средний

6.5 Medium

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 4.8
redhat
около 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
nvd
почти 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS3: 6.5
debian
почти 9 лет назад

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before ...

suse-cvrf
почти 9 лет назад

Security update for python

EPSS

Процентиль: 93%
0.10435
Средний

6.5 Medium

CVSS3

Дефекты

CWE-693