The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade python | Aug 30, 2017 | Sep 2, 2016 |
| Amazon_linux | — | Upgrade python34Upgrade python27Upgrade python26 | Jul 22, 2016 | Jul 20, 2016 |
| Centos_linux | — | Upgrade python-develUpgrade python-toolsUpgrade tkinterUpgrade python-libsUpgrade python-testUpgrade python-debugUpgrade python | Aug 22, 2016 | Aug 18, 2016 |
| Debian | — | Upgrade python3.2Upgrade python2.7 | Mar 31, 2017 | Sep 2, 2016 |
| Freebsd | — | Upgrade python27Upgrade python34Upgrade python33Upgrade python35 | Dec 10, 2025 | Jul 3, 2016 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Sep 2, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade python-develUpgrade python-libsUpgrade python | Nov 30, 2017 | Sep 2, 2016 |
| Oracle Solaris | — | Upgrade runtime/python-34 to version 3.4.3-0.175.3.10.0.3.0 on Solaris 11.3Upgrade runtime/python-27 to version 2.7.9-0.175.3.10.0.3.0 on Solaris 11.3 | May 29, 2017 | Sep 2, 2016 |
| Oracle_linux | — | Upgrade python-toolsUpgrade pythonUpgrade tkinterUpgrade python-testUpgrade python-debugUpgrade python-libsUpgrade python-devel | Sep 2, 2016 | Jun 11, 2016 |
| Redhat_linux | — | Upgrade python-debuginfoNo solution existsUpgrade python-debugUpgrade python-libsUpgrade python-develUpgrade tkinterUpgrade python-testUpgrade pythonUpgrade python-tools | Aug 22, 2016 | Aug 18, 2016 |
| Suse | — | Upgrade libpython2_6-1_0-32bitUpgrade python-tkUpgrade python-idleUpgrade python3-base-32bitUpgrade libpython2_6-1_0Upgrade libpython2_6-1_0-x86Upgrade python-32bitUpgrade libpython2_7-1_0Upgrade python-x86Upgrade pythonUpgrade python-base-x86Upgrade python3Upgrade python3-tkUpgrade python3-toolsUpgrade libpython3_4m1_0-32bitUpgrade python3-testsuiteUpgrade python-xmlUpgrade python3-dbmUpgrade python-baseUpgrade python-demoUpgrade python3-cursesUpgrade python-gdbmUpgrade python-doc-pdfUpgrade python-base-32bitUpgrade python3-idleUpgrade libpython3_4m1_0Upgrade python3-develUpgrade libpython3_6m1_0Upgrade python-develUpgrade python3-baseUpgrade python3-32bitUpgrade python-docUpgrade libpython3_6m1_0-32bitUpgrade libpython2_7-1_0-32bitUpgrade python-curses | Sep 2, 2016 | Sep 2, 2016 |
| Ubuntu | — | Upgrade python3.5-minimalUpgrade python3.2Upgrade libpython2.7Upgrade libpython3.4-stdlibUpgrade python3.4-minimalUpgrade libpython2.7-stdlibUpgrade libpython3.5-stdlibUpgrade libpython3.2Upgrade python2.7Upgrade libpython2.7-minimalUpgrade libpython3.5Upgrade python3.2-minimalUpgrade libpython3.4Upgrade libpython3.5-minimalUpgrade python3.5Upgrade python3.4Upgrade python2.7-minimalUpgrade libpython3.4-minimal | Nov 23, 2016 | Sep 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub