Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhf3-pp4q-gxh5

Опубликовано: 17 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

EPSS

Процентиль: 59%
0.00393
Низкий

7.4 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 1 года назад

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

CVSS3: 5
redhat
около 1 года назад

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

CVSS3: 7.4
nvd
около 1 года назад

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

CVSS3: 7.4
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 7.4
debian
около 1 года назад

A defect was discovered in the Python \u201cssl\u201d module where the ...

EPSS

Процентиль: 59%
0.00393
Низкий

7.4 High

CVSS3

Дефекты

CWE-362