Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-develUpgrade python-toolsUpgrade python-libsUpgrade tkinterUpgrade pythonUpgrade python-docs | Dec 1, 2016 | Oct 19, 2010 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Oct 19, 2010 |
| Oracle_linux | — | Upgrade python-libsUpgrade pythonUpgrade python-testUpgrade tkinterUpgrade python-develUpgrade python-docsUpgrade python-tools | Oct 16, 2024 | Oct 19, 2010 |
| Redhat_linux | — | — | Jul 9, 2025 | Jun 30, 2010 |
| Suse | — | Upgrade python-x86Upgrade python-develUpgrade python-idleUpgrade libpython2_6-1_0Upgrade python-32bitUpgrade python-gdbmUpgrade python-base-32bitUpgrade python-xmlUpgrade pythonUpgrade libpython2_6-1_0-x86Upgrade python-demoUpgrade python-baseUpgrade python-cursesUpgrade python-base-x86Upgrade libpython2_6-1_0-32bitUpgrade python-tk | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python2.4-minimalUpgrade python3.1-minimalUpgrade python2.4Upgrade python2.6Upgrade python2.5-minimalUpgrade python2.6-minimalUpgrade python2.5 | Nov 8, 2024 | Oct 19, 2010 |
| Vmsa 2012 0001 | — | Upgrade VMware ESX 4.0 to build number 660575Upgrade VMware ESX 4.1 to build number 582267 | Feb 3, 2012 | Oct 19, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub