CVE-2013-4238
python: hostname check bypassing vulnerability in SSL module
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
La función ssl.match_hostname en el módulo SSL en Python v2.6 hasta v3.4 no manejar adecuadamente un carácter “\0” en un nombre de dominio en el campo Subject Alternative Name de un certificado X.509, lo que permite a atacantes "man-in-the-middle" suplantar servidores SSL de su elección mediante un certificado manipulado expedido por una Autoridad Certificadora legítima, un problema relacionado con CVE-2009-2408
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-06-12 CVE Reserved
- 2013-08-18 CVE Published
- 2023-03-30 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2014/Dec/23 | Mailing List | |
http://www.securityfocus.com/archive/1/534161/100/0/threaded | Mailing List | |
http://www.vmware.com/security/advisories/VMSA-2014-0012.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bugs.python.org/issue18709 | 2019-10-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=996381 | 2013-11-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 10.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "10.04" | lts |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.1 Search vendor "Python" for product "Python" and version "2.6.1" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.2 Search vendor "Python" for product "Python" and version "2.6.2" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.3 Search vendor "Python" for product "Python" and version "2.6.3" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.4 Search vendor "Python" for product "Python" and version "2.6.4" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.5 Search vendor "Python" for product "Python" and version "2.6.5" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.6 Search vendor "Python" for product "Python" and version "2.6.6" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.7 Search vendor "Python" for product "Python" and version "2.6.7" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.8 Search vendor "Python" for product "Python" and version "2.6.8" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.2150 Search vendor "Python" for product "Python" and version "2.6.2150" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.6.6150 Search vendor "Python" for product "Python" and version "2.6.6150" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.7.1 Search vendor "Python" for product "Python" and version "2.7.1" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.7.1 Search vendor "Python" for product "Python" and version "2.7.1" | rc1 |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.7.2 Search vendor "Python" for product "Python" and version "2.7.2" | rc1 |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.7.3 Search vendor "Python" for product "Python" and version "2.7.3" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.7.1150 Search vendor "Python" for product "Python" and version "2.7.1150" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.7.1150 Search vendor "Python" for product "Python" and version "2.7.1150" | x64 |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 2.7.2150 Search vendor "Python" for product "Python" and version "2.7.2150" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.0 Search vendor "Python" for product "Python" and version "3.0" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.0.1 Search vendor "Python" for product "Python" and version "3.0.1" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.1 Search vendor "Python" for product "Python" and version "3.1" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.1.1 Search vendor "Python" for product "Python" and version "3.1.1" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.1.2 Search vendor "Python" for product "Python" and version "3.1.2" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.1.3 Search vendor "Python" for product "Python" and version "3.1.3" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.1.4 Search vendor "Python" for product "Python" and version "3.1.4" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.1.5 Search vendor "Python" for product "Python" and version "3.1.5" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.1.2150 Search vendor "Python" for product "Python" and version "3.1.2150" | x64 |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.2 Search vendor "Python" for product "Python" and version "3.2" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.2 Search vendor "Python" for product "Python" and version "3.2" | alpha |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.2.3 Search vendor "Python" for product "Python" and version "3.2.3" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.2.2150 Search vendor "Python" for product "Python" and version "3.2.2150" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.3 Search vendor "Python" for product "Python" and version "3.3" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.3 Search vendor "Python" for product "Python" and version "3.3" | beta2 |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | 3.4 Search vendor "Python" for product "Python" and version "3.4" | alpha1 |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 11.4 Search vendor "Opensuse" for product "Opensuse" and version "11.4" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 12.2 Search vendor "Opensuse" for product "Opensuse" and version "12.2" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 12.3 Search vendor "Opensuse" for product "Opensuse" and version "12.3" | - |
Affected
|