Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 33

Количество 33

fstec логотип

BDU:2023-05002

около 3 лет назад

Уязвимость класса SSLSocket интерпретатора языка программирования Python, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.6
EPSS: Низкий
redos логотип

ROS-20240409-02

больше 2 лет назад

Множественные уязвимости python3

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2023-6199

почти 3 года назад

ALT-PU-2023-6199: package `python3` update to version 3.11.6-alt1

CVSS3: 8.6
EPSS: Низкий
altlinux логотип

ALT-PU-2024-2511

больше 2 лет назад

ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-40217

около 3 лет назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-40217

около 3 лет назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2023-40217

около 3 лет назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-40217

почти 3 года назад

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-40217

около 3 лет назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3933-1

около 3 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3828-1

около 3 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3824-1

около 3 лет назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3804-1

около 3 лет назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3731-1

около 3 лет назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3730-1

около 3 лет назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3708-1

около 3 лет назад

Security update for python39

EPSS: Низкий
rocky логотип

RLSA-2023:5998

7 месяцев назад

Important: python39:3.9 and python39-devel:3.9 security update

EPSS: Низкий
rocky логотип

RLSA-2023:5997

почти 3 года назад

Important: python3 security update

EPSS: Низкий
rocky логотип

RLSA-2023:5994

7 месяцев назад

Important: python27:2.7 security update

EPSS: Низкий
rocky логотип

RLSA-2023:5463

почти 3 года назад

Important: python3.11 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-05002

Уязвимость класса SSLSocket интерпретатора языка программирования Python, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.6
1%
Низкий
около 3 лет назад
redos логотип
ROS-20240409-02

Множественные уязвимости python3

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2023-6199

ALT-PU-2023-6199: package `python3` update to version 3.11.6-alt1

CVSS3: 8.6
почти 3 года назад
altlinux логотип
ALT-PU-2024-2511

ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1

CVSS3: 9.8
больше 2 лет назад
ubuntu логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 8.6
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
1%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 5.3
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-40217

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ...

CVSS3: 5.3
1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3933-1

Security update for python

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3828-1

Security update for python3

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3824-1

Security update for python310

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3804-1

Security update for python3

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3731-1

Security update for python36

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3730-1

Security update for python

1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3708-1

Security update for python39

1%
Низкий
около 3 лет назад
rocky логотип
RLSA-2023:5998

Important: python39:3.9 and python39-devel:3.9 security update

1%
Низкий
7 месяцев назад
rocky логотип
RLSA-2023:5997

Important: python3 security update

1%
Низкий
почти 3 года назад
rocky логотип
RLSA-2023:5994

Important: python27:2.7 security update

1%
Низкий
7 месяцев назад
rocky логотип
RLSA-2023:5463

Important: python3.11 security update

1%
Низкий
почти 3 года назад

Уязвимостей на страницу