Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-7440

Опубликовано: 07 июн. 2016
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.9

Описание

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

not-affected

contains the RFC 6125 code change
precise

not-affected

doesn't implement ssl.match_hostname
trusty

not-affected

contains the RFC 6125 code change
trusty/esm

not-affected

contains the RFC 6125 code change
upstream

needs-triage

utopic

not-affected

vivid

not-affected

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

precise

ignored

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

utopic

DNE

vivid

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

not-affected

contains the RFC 6125 code change
precise

DNE

trusty

not-affected

contains the RFC 6125 code change
trusty/esm

not-affected

contains the RFC 6125 code change
upstream

needs-triage

utopic

not-affected

vivid

not-affected

Показывать по

EPSS

Процентиль: 67%
0.00557
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

redhat
почти 12 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS3: 5.9
nvd
около 9 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS3: 5.9
debian
около 9 лет назад

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 a ...

suse-cvrf
почти 10 лет назад

Recommended update for python-setuptools

suse-cvrf
почти 10 лет назад

Security update for python-setuptools

EPSS

Процентиль: 67%
0.00557
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Уязвимость CVE-2013-7440