Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linkcheckerUpgrade python2.7Upgrade python-tornadoUpgrade python-urllib3Upgrade bzr | Jul 30, 2024 | Oct 9, 2013 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Oct 9, 2013 |
| Oracle Solaris | — | Upgrade runtime/python-26 to version 2.6.8-0.175.1.12.0.3.0 on Solaris 11.1 | May 29, 2017 | Oct 9, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 15, 2013 |
| Suse | — | Upgrade libpython3_3m1_0Upgrade python3-cursesUpgrade python3-testsuiteUpgrade libpython3_3m1_0-32bitUpgrade python3-dbmUpgrade python3-toolsUpgrade python3-doc-pdfUpgrade python3-tkUpgrade python3-32bitUpgrade python3-develUpgrade python3-base-32bitUpgrade python3Upgrade python3-idleUpgrade python3-baseUpgrade python3-doc | Sep 30, 2014 | Oct 9, 2013 |
| Ubuntu | — | Upgrade python3.3-minimalUpgrade python3.2-minimalUpgrade python3.3Upgrade python2.7-minimalUpgrade python2.7Upgrade python3.2 | Nov 8, 2024 | Oct 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub