Количество 33
Количество 33
BDU:2023-05002
Уязвимость класса SSLSocket интерпретатора языка программирования Python, позволяющая нарушителю раскрыть защищаемую информацию
ROS-20240409-02
Множественные уязвимости python3
ALT-PU-2023-6199
ALT-PU-2023-6199: package `python3` update to version 3.11.6-alt1
ALT-PU-2024-2511
ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1
CVE-2023-40217
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
CVE-2023-40217
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
CVE-2023-40217
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
CVE-2023-40217
CVE-2023-40217
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ...
SUSE-SU-2023:3933-1
Security update for python
SUSE-SU-2023:3828-1
Security update for python3
SUSE-SU-2023:3824-1
Security update for python310
SUSE-SU-2023:3804-1
Security update for python3
SUSE-SU-2023:3731-1
Security update for python36
SUSE-SU-2023:3730-1
Security update for python
SUSE-SU-2023:3708-1
Security update for python39
RLSA-2023:5998
Important: python39:3.9 and python39-devel:3.9 security update
RLSA-2023:5997
Important: python3 security update
RLSA-2023:5994
Important: python27:2.7 security update
RLSA-2023:5463
Important: python3.11 security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2023-05002 Уязвимость класса SSLSocket интерпретатора языка программирования Python, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 8.6 | 1% Низкий | около 3 лет назад | |
ROS-20240409-02 Множественные уязвимости python3 | CVSS3: 9.8 | больше 2 лет назад | ||
ALT-PU-2023-6199 ALT-PU-2023-6199: package `python3` update to version 3.11.6-alt1 | CVSS3: 8.6 | почти 3 года назад | ||
ALT-PU-2024-2511 ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
CVE-2023-40217 An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.) | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
CVE-2023-40217 An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.) | CVSS3: 8.6 | 1% Низкий | около 3 лет назад | |
CVE-2023-40217 An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.) | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
CVSS3: 5.3 | 1% Низкий | почти 3 года назад | ||
CVE-2023-40217 An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ... | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
SUSE-SU-2023:3933-1 Security update for python | 1% Низкий | около 3 лет назад | ||
SUSE-SU-2023:3828-1 Security update for python3 | 1% Низкий | около 3 лет назад | ||
SUSE-SU-2023:3824-1 Security update for python310 | 1% Низкий | около 3 лет назад | ||
SUSE-SU-2023:3804-1 Security update for python3 | 1% Низкий | около 3 лет назад | ||
SUSE-SU-2023:3731-1 Security update for python36 | 1% Низкий | около 3 лет назад | ||
SUSE-SU-2023:3730-1 Security update for python | 1% Низкий | около 3 лет назад | ||
SUSE-SU-2023:3708-1 Security update for python39 | 1% Низкий | около 3 лет назад | ||
RLSA-2023:5998 Important: python39:3.9 and python39-devel:3.9 security update | 1% Низкий | 7 месяцев назад | ||
RLSA-2023:5997 Important: python3 security update | 1% Низкий | почти 3 года назад | ||
RLSA-2023:5994 Important: python27:2.7 security update | 1% Низкий | 7 месяцев назад | ||
RLSA-2023:5463 Important: python3.11 security update | 1% Низкий | почти 3 года назад |
Уязвимостей на страницу