Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9015

Опубликовано: 11 янв. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 3.7

Описание

Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

not-affected

esm-infra/xenial

not-affected

precise

DNE

trusty

not-affected

trusty/esm

not-affected

upstream

released

1.18.1
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

not-affected

xenial

not-affected

Показывать по

EPSS

Процентиль: 18%
0.00058
Низкий

2.6 Low

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
около 9 лет назад

Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.

CVSS3: 3.7
debian
около 9 лет назад

Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vul ...

suse-cvrf
почти 7 лет назад

Security update for python-urllib3

suse-cvrf
около 7 лет назад

Security update for python-urllib3

suse-cvrf
больше 6 лет назад

Recommended update for python-setuptools and dependend packages

EPSS

Процентиль: 18%
0.00058
Низкий

2.6 Low

CVSS2

3.7 Low

CVSS3