PT-2013-4953 · Openssl · Pyopenssl

Christian Heimes

·

Published

2013-09-13

·

Updated

2024-07-12

·

CVE-2013-4314

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pyOpenSSL versions prior to 0.13.1
Description The issue arises from the improper handling of a 0 character in a domain name within the Subject Alternative Name field of an X.509 certificate by the X509Extension in pyOpenSSL. This allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Recommendations For pyOpenSSL versions prior to 0.13.1, update to version 0.13.1 or later to resolve the issue. As a temporary workaround, consider restricting the acceptance of certificates with domain names containing the 0 character in the Subject Alternative Name field.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2013-4314
DSA-2763-1
GHSA-6748-36QP-FX6R
MGASA-2013-0277
OPENSUSE-SU-2024:10214-1
OPENSUSE-SU-2024:11253-1
OPENSUSE-SU-2024:14154-1
PYSEC-2013-31
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1

Affected Products

Pyopenssl