Количество 18
Количество 18
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remo ...
SUSE-SU-2024:3298-1
Security update for python-dnspython
SUSE-SU-2024:3297-1
Security update for python-dnspython
SUSE-SU-2024:2655-1
Security update for python-dnspython
SUSE-SU-2024:2626-1
Security update for python-dnspython
SUSE-SU-2024:2605-1
Security update for python-dnspython
SUSE-RU-2026:2816-1
Recommended update for python-aioresponses, python-google-api-core, python-google-api-python-client, python-google-auth, python-google-auth-httplib2, python-google-cloud-appengine-logging, python-google-cloud-artifact-registry, python-google-cloud-audit-log, python-google-cloud-build, python-google-cloud-compute, python-google-cloud-core, python-google-cloud-dns, python-google-cloud-domains, python-google-cloud-iam, python-google-cloud-kms, python-google-cloud-kms-inventory, python-google-cloud-logging, python-google-cloud-run, python-google-cloud-secret-manager, python-google-cloud-service-directory, python-google-cloud-spanner, python-google-cloud-storage, python-google-cloud-vpc-access, python-google-crc32c, python-google-resumable-media, python-googleapis-common-protos, python-grpc-google-iam-v1, python-grpc-interceptor, python-mmh3, python-mypy, python-opentelemetry-resourcedetector-gcp, python-poetry-core, python-proto-plus, python-pytest-asyncio, python-syrupy, python-typed-ast, python-uritemplate, python-dnspython, python-trio, python-websocket-client
RLSA-2024:9423
Moderate: python-dns security update
RLSA-2024:3275
Moderate: python-dns security update
GHSA-3rq5-2g8h-59hc
Potential DoS via the Tudoor mechanism in eventlet and dnspython
ELSA-2024-9423
ELSA-2024-9423: python-dns security update (MODERATE)
ELSA-2024-3275
ELSA-2024-3275: python-dns security update (MODERATE)
BDU:2025-03301
Уязвимость набора инструментов для Python dnspython, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20250226-01
Уязвимость python3-eventlet
ROS-20250212-08
Уязвимость python3-dns
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-29483 eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. | CVSS3: 7 | 2% Низкий | больше 2 лет назад | |
CVE-2023-29483 eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. | CVSS3: 5.9 | 2% Низкий | больше 2 лет назад | |
CVE-2023-29483 eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. | CVSS3: 7 | 2% Низкий | больше 2 лет назад | |
CVE-2023-29483 eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remo ... | CVSS3: 7 | 2% Низкий | больше 2 лет назад | |
SUSE-SU-2024:3298-1 Security update for python-dnspython | 2% Низкий | почти 2 года назад | ||
SUSE-SU-2024:3297-1 Security update for python-dnspython | 2% Низкий | почти 2 года назад | ||
SUSE-SU-2024:2655-1 Security update for python-dnspython | 2% Низкий | около 2 лет назад | ||
SUSE-SU-2024:2626-1 Security update for python-dnspython | 2% Низкий | около 2 лет назад | ||
SUSE-SU-2024:2605-1 Security update for python-dnspython | 2% Низкий | около 2 лет назад | ||
SUSE-RU-2026:2816-1 Recommended update for python-aioresponses, python-google-api-core, python-google-api-python-client, python-google-auth, python-google-auth-httplib2, python-google-cloud-appengine-logging, python-google-cloud-artifact-registry, python-google-cloud-audit-log, python-google-cloud-build, python-google-cloud-compute, python-google-cloud-core, python-google-cloud-dns, python-google-cloud-domains, python-google-cloud-iam, python-google-cloud-kms, python-google-cloud-kms-inventory, python-google-cloud-logging, python-google-cloud-run, python-google-cloud-secret-manager, python-google-cloud-service-directory, python-google-cloud-spanner, python-google-cloud-storage, python-google-cloud-vpc-access, python-google-crc32c, python-google-resumable-media, python-googleapis-common-protos, python-grpc-google-iam-v1, python-grpc-interceptor, python-mmh3, python-mypy, python-opentelemetry-resourcedetector-gcp, python-poetry-core, python-proto-plus, python-pytest-asyncio, python-syrupy, python-typed-ast, python-uritemplate, python-dnspython, python-trio, python-websocket-client | 2% Низкий | 24 дня назад | ||
RLSA-2024:9423 Moderate: python-dns security update | 2% Низкий | больше 1 года назад | ||
RLSA-2024:3275 Moderate: python-dns security update | 2% Низкий | около 2 лет назад | ||
GHSA-3rq5-2g8h-59hc Potential DoS via the Tudoor mechanism in eventlet and dnspython | CVSS3: 5.9 | 2% Низкий | больше 2 лет назад | |
ELSA-2024-9423 ELSA-2024-9423: python-dns security update (MODERATE) | 2% Низкий | больше 1 года назад | ||
ELSA-2024-3275 ELSA-2024-3275: python-dns security update (MODERATE) | 2% Низкий | около 2 лет назад | ||
BDU:2025-03301 Уязвимость набора инструментов для Python dnspython, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7 | 2% Низкий | больше 2 лет назад | |
ROS-20250226-01 Уязвимость python3-eventlet | CVSS2: 6.6 | 2% Низкий | больше 1 года назад | |
ROS-20250212-08 Уязвимость python3-dns | CVSS2: 6.6 | 2% Низкий | больше 1 года назад |
Уязвимостей на страницу