Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-5010

Опубликовано: 15 янв. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.

A null pointer dereference vulnerability was found in the certificate parsing code in Python. This causes a denial of service to applications when parsing specially crafted certificates. This vulnerability is unlikely to be triggered if application enables SSL/TLS certificate validation and accepts certificates only from trusted root certificate authorities.

Отчет

This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5 and 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonNot affected
Red Hat Enterprise Linux 6pythonNot affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Software Collectionsrh-python35-pythonWill not fix
Red Hat Ansible Tower 3.4 for RHEL 7ansible-tower-34/ansible-tower-memcachedFixedRHBA-2020:054718.02.2020
Red Hat Ansible Tower 3.4 for RHEL 7ansible-tower-35/ansible-tower-memcachedFixedRHBA-2020:054718.02.2020
Red Hat Ansible Tower 3.4 for RHEL 7ansible-tower-37/ansible-tower-memcached-rhel7FixedRHBA-2020:054718.02.2020
Red Hat Enterprise Linux 7pythonFixedRHSA-2019:203006.08.2019
Red Hat Enterprise Linux 8python3FixedRHSA-2019:352005.11.2019
Red Hat Enterprise Linux 8python3FixedRHSA-2019:352005.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1666519python: NULL pointer dereference using a specially crafted X509 certificate

EPSS

Процентиль: 87%
0.03652
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.

CVSS3: 7.5
nvd
больше 5 лет назад

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.

CVSS3: 7.5
debian
больше 5 лет назад

An exploitable denial-of-service vulnerability exists in the X509 cert ...

suse-cvrf
около 6 лет назад

Security update for python

suse-cvrf
больше 6 лет назад

Security update for python

EPSS

Процентиль: 87%
0.03652
Низкий

7.5 High

CVSS3