The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Details
- CVSS 3.1 Base Score: 3.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python2.7 | Jul 30, 2024 | Aug 18, 2013 |
| Oracle Solaris | — | Upgrade runtime/python-26 to version 2.6.8-0.175.1.12.0.3.0 on Solaris 11.1 | May 29, 2017 | Aug 17, 2013 |
| Oracle_linux | — | Upgrade python-develUpgrade python-toolsUpgrade pythonUpgrade tkinterUpgrade python-libsUpgrade python-test | Oct 16, 2024 | Aug 18, 2013 |
| Suse | — | Upgrade python-cursesUpgrade python3-tkUpgrade libpython3_3m1_0-32bitUpgrade python3-2to3Upgrade python3-xmlUpgrade python3-testsuiteUpgrade libpython3_2mu1_0-32bitUpgrade python3-base-32bitUpgrade python-develUpgrade python3-32bitUpgrade python-base-x86Upgrade libpython3_3m1_0Upgrade python-demoUpgrade python-doc-pdfUpgrade python3-dbmUpgrade libpython2_6-1_0-32bitUpgrade python-idleUpgrade python-base-32bitUpgrade python3-toolsUpgrade sle-sdk-releaseUpgrade python3-idleUpgrade pythonUpgrade python3-docUpgrade python-baseUpgrade libpython3_2mu1_0Upgrade libpython2_7-1_0-32bitUpgrade python-xmlUpgrade python-gdbmUpgrade libpython2_7-1_0Upgrade python-x86Upgrade python3-cursesUpgrade libpython2_6-1_0Upgrade python3-develUpgrade python3Upgrade python3-baseUpgrade python-docUpgrade libpython2_6-1_0-x86Upgrade python3-doc-pdfUpgrade python-32bitUpgrade python-tk | Dec 12, 2013 | Aug 17, 2013 |
| Ubuntu | — | Upgrade python2.6Upgrade python2.6-minimalUpgrade python2.7Upgrade python3.2-minimalUpgrade python2.7-minimalUpgrade python3.3-minimalUpgrade python3.2Upgrade python3.3 | Nov 8, 2024 | Aug 18, 2013 |
| Vmsa 2014 0012 | — | Upgrade VMware ESXi 5.5 to build number 2068190Upgrade VMware ESXi 5.1 to build number 2323236 | Oct 28, 2015 | Aug 17, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub