Описание
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to set_tlsext_servername_callback raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 25.3.0-1ubuntu1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | released | 0.15.1-2ubuntu0.2+esm1 |
| esm-infra/bionic | released | 17.5.0-1ubuntu1+esm1 |
| esm-infra/focal | released | 19.0.0-1ubuntu0.1~esm1 |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | released | 21.0.0-1ubuntu0.1 |
| noble | released | 23.2.0-1ubuntu0.1 |
| questing | released | 25.0.0-1ubuntu0.1 |
| resolute | not-affected | 25.3.0-1ubuntu1 |
Показывать по
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.
pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...
EPSS
5.3 Medium
CVSS3