Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-develUpgrade python-libsUpgrade tkinterUpgrade python-toolsUpgrade pythonUpgrade python-docs | Dec 1, 2016 | Oct 19, 2010 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Oct 19, 2010 |
| Oracle_linux | — | Upgrade tkinterUpgrade python-testUpgrade pythonUpgrade python-libsUpgrade python-toolsUpgrade python-develUpgrade python-docs | Oct 16, 2024 | Oct 19, 2010 |
| Redhat_linux | — | — | Jul 9, 2025 | Jun 30, 2010 |
| Suse | — | Upgrade libpython2_6-1_0-32bitUpgrade python-demoUpgrade python-cursesUpgrade python-baseUpgrade python-xmlUpgrade python-tkUpgrade pythonUpgrade libpython2_6-1_0-x86Upgrade python-base-x86Upgrade python-32bitUpgrade python-base-32bitUpgrade python-gdbmUpgrade python-x86Upgrade python-develUpgrade libpython2_6-1_0Upgrade python-idle | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python3.1-minimalUpgrade python2.4Upgrade python2.5-minimalUpgrade python2.6Upgrade python2.4-minimalUpgrade python2.5Upgrade python2.6-minimal | Nov 8, 2024 | Oct 19, 2010 |
| Vmsa 2012 0001 | — | Upgrade VMware ESX 4.0 to build number 660575Upgrade VMware ESX 4.1 to build number 582267 | Feb 3, 2012 | Oct 19, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub