PT-2010-4860 · Python · Python

Steven M. Christey

·

Publicado

2010-10-19

·

Atualizado

2019-10-29

·

CVE-2010-3492

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Python versions prior to 3.2
Description The issue concerns the asyncore module in Python, which does not properly handle unsuccessful calls to the accept function. This lack of proper handling, combined with the absence of documentation on how daemon applications should manage such unsuccessful calls, facilitates denial of service attacks. These attacks can terminate daemon applications via network connections.
Recommendations For versions prior to 3.2, consider updating to a version that properly handles unsuccessful calls to the accept function to prevent denial of service attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-3492
PSF-2010-6

Produtos afetados

Python