Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3492

Опубликовано: 09 сент. 2010
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.

Отчет

This issue affects the version of the python package as shipped with Red Hat Enterprise Linux 4, 5, and 6. Due to the nature of this flaw, it cannot be fixed in the python language, but must be addressed in each module which calls accept().

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3pythonAffected
Red Hat Enterprise Linux 4pythonAffected
Red Hat Enterprise Linux 5pythonAffected
Red Hat Enterprise Linux 6pythonAffected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=638330python accept() implementation in async core is broken

EPSS

Процентиль: 79%
0.01275
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.

nvd
больше 14 лет назад

The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.

debian
больше 14 лет назад

The asyncore module in Python before 3.2 does not properly handle unsu ...

github
около 3 лет назад

The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.

EPSS

Процентиль: 79%
0.01275
Низкий

5 Medium

CVSS2

Уязвимость CVE-2010-3492