PT-2013-3541 · Python+1 · Python+2

Florian Weimer

+1

·

Published

2013-05-16

·

Updated

2023-02-13

·

CVE-2013-2099

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Python versions prior to 3.4 python-backports-ssl match hostname (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service, specifically CPU consumption, by exploiting the ssl.match hostname function. This is achieved through the use of multiple wildcard characters in the common name of a certificate.
Recommendations For Python versions prior to 3.4, update to version 3.4 or later to resolve the issue. For python-backports-ssl match hostname, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1294
CVE-2013-2099
DLA-1107-1
MGASA-2013-0252
PSF-2013-1
RHSA-2014:1263
RHSA-2014:1690
RHSA-2015:0042
RHSA-2016:1166
USN-1983-1
USN-1984-1
USN-1985-1

Affected Products

Alt Linux
Python
Python-Backports-Ssl Match Hostname