Количество 33
Количество 33
GHSA-4j9r-82g6-9mj3
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
ELSA-2023-6885
ELSA-2023-6885: python security update (IMPORTANT)
ELSA-2023-6823
ELSA-2023-6823: python3 security update (IMPORTANT)
ELSA-2023-5998
ELSA-2023-5998: python39:3.9 and python39-devel:3.9 security update (IMPORTANT)
ELSA-2023-5997
ELSA-2023-5997: python3 security update (IMPORTANT)
ELSA-2023-5994
ELSA-2023-5994: python27:2.7 security update (IMPORTANT)
ELSA-2023-5463
ELSA-2023-5463: python3.11 security update (IMPORTANT)
ELSA-2023-5462
ELSA-2023-5462: python3.9 security update (IMPORTANT)
ELSA-2023-5456
ELSA-2023-5456: python3.11 security update (IMPORTANT)
SUSE-SU-2024:0785-1
Security update for python3
SUSE-SU-2023:3943-1
Security update for python311
SUSE-SU-2023:3939-1
Security update for python3
SUSE-SU-2024:0784-1
Security update for python39
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4j9r-82g6-9mj3 An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.) | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
ELSA-2023-6885 ELSA-2023-6885: python security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
ELSA-2023-6823 ELSA-2023-6823: python3 security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
ELSA-2023-5998 ELSA-2023-5998: python39:3.9 and python39-devel:3.9 security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
ELSA-2023-5997 ELSA-2023-5997: python3 security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
ELSA-2023-5994 ELSA-2023-5994: python27:2.7 security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
ELSA-2023-5463 ELSA-2023-5463: python3.11 security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
ELSA-2023-5462 ELSA-2023-5462: python3.9 security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
ELSA-2023-5456 ELSA-2023-5456: python3.11 security update (IMPORTANT) | 1% Низкий | почти 3 года назад | ||
SUSE-SU-2024:0785-1 Security update for python3 | больше 2 лет назад | |||
SUSE-SU-2023:3943-1 Security update for python311 | около 3 лет назад | |||
SUSE-SU-2023:3939-1 Security update for python3 | около 3 лет назад | |||
SUSE-SU-2024:0784-1 Security update for python39 | больше 2 лет назад |
Уязвимостей на страницу