The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Details
- CVSS 3.1 Base Score: 3.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python2.7 | Jul 30, 2024 | Aug 18, 2013 |
| Oracle Solaris | — | Upgrade runtime/python-26 to version 2.6.8-0.175.1.12.0.3.0 on Solaris 11.1 | May 29, 2017 | Aug 17, 2013 |
| Oracle_linux | — | Upgrade python-toolsUpgrade python-develUpgrade tkinterUpgrade pythonUpgrade python-libsUpgrade python-test | Oct 16, 2024 | Aug 18, 2013 |
| Suse | — | Upgrade libpython3_3m1_0Upgrade python-demoUpgrade python3-docUpgrade libpython2_7-1_0-32bitUpgrade python-tkUpgrade python3-toolsUpgrade python3-idleUpgrade sle-sdk-releaseUpgrade libpython2_6-1_0-x86Upgrade python3-doc-pdfUpgrade python-base-32bitUpgrade python-x86Upgrade libpython2_6-1_0Upgrade python-idleUpgrade libpython2_6-1_0-32bitUpgrade python3-dbmUpgrade python3Upgrade python-xmlUpgrade libpython2_7-1_0Upgrade python3-baseUpgrade python-doc-pdfUpgrade libpython3_2mu1_0Upgrade python-gdbmUpgrade python3-cursesUpgrade python-baseUpgrade python3-develUpgrade python-32bitUpgrade python-base-x86Upgrade pythonUpgrade python-docUpgrade python-develUpgrade python3-2to3Upgrade python-cursesUpgrade python3-xmlUpgrade python3-testsuiteUpgrade libpython3_2mu1_0-32bitUpgrade python3-32bitUpgrade python3-base-32bitUpgrade libpython3_3m1_0-32bitUpgrade python3-tk | Dec 12, 2013 | Aug 17, 2013 |
| Ubuntu | — | Upgrade python2.7Upgrade python3.3-minimalUpgrade python2.7-minimalUpgrade python3.2-minimalUpgrade python2.6Upgrade python2.6-minimalUpgrade python3.2Upgrade python3.3 | Nov 8, 2024 | Aug 18, 2013 |
| Vmsa 2014 0012 | — | Upgrade VMware ESXi 5.1 to build number 2323236Upgrade VMware ESXi 5.5 to build number 2068190 | Oct 28, 2015 | Aug 17, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub