Описание
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
Multiple flaws were found in the way Python's SSL module performed matching of certificate names containing wildcards. A remote attacker able to obtain a valid certificate that contained certain names with wildcards could have them incorrectly accepted by Python SSL clients, not following the RFC 6125 recommendations.
Отчет
This issue affects the versions of python27-python-pip, python-pymongo and python-virtualenv as shipped with Red Hat OpenShift 2.x and Satellite 6. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ceph Storage 1.1 | python-backports-ssl_match_hostname | Not affected | ||
Red Hat Ceph Storage 1.2 | python-backports-ssl_match_hostname | Not affected | ||
Red Hat Enterprise Linux 5 | python | Not affected | ||
Red Hat Enterprise Linux 5 | python-setuptools | Not affected | ||
Red Hat Enterprise Linux 6 | bzr | Not affected | ||
Red Hat Enterprise Linux 6 | python | Not affected | ||
Red Hat Enterprise Linux 6 | python-backports-ssl_match_hostname | Not affected | ||
Red Hat Enterprise Linux 6 | python-setuptools | Not affected | ||
Red Hat Enterprise Linux 7 | bzr | Will not fix | ||
Red Hat Enterprise Linux 7 | python | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4 Medium
CVSS2
Связанные уязвимости
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 a ...
EPSS
4 Medium
CVSS2