CVE-2013-2099
published 2013-10-09CVE-2013-2099: Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.86%
91.0th percentile
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bzr | < bzr 2.6.0~bzr6574-1 (bookworm) | bzr 2.6.0~bzr6574-1 (bookworm) |
| debian | linkchecker | < bzr 2.6.0~bzr6574-1 (bookworm) | bzr 2.6.0~bzr6574-1 (bookworm) |
| debian | python-tornado | < bzr 2.6.0~bzr6574-1 (bookworm) | bzr 2.6.0~bzr6574-1 (bookworm) |
| debian | python-urllib3 | < bzr 2.6.0~bzr6574-1 (bookworm) | bzr 2.6.0~bzr6574-1 (bookworm) |
| debian | python2.7 | < bzr 2.6.0~bzr6574-1 (bookworm) | bzr 2.6.0~bzr6574-1 (bookworm) |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cqcg-qrcv-vr6v: Algorithmic complexity vulnerability in the ssl
ghsa_unreviewed·2022-05-17
CVE-2013-2099 [MEDIUM] GHSA-cqcg-qrcv-vr6v: Algorithmic complexity vulnerability in the ssl
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
OSV
CVE-2013-2099: Algorithmic complexity vulnerability in the ssl
osv·2013-10-09·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099: Algorithmic complexity vulnerability in the ssl
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
Ubuntu
Python 3.3 vulnerabilities
vendor_ubuntu·2013-10-01·CVSS 4.3
CVE-2013-2099 [MEDIUM] Python 3.3 vulnerabilities
Title: Python 3.3 vulnerabilities
Summary: Several security issues were fixed in Python.
Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service.
(CVE-2013-2099)
Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python 2.7 vulnerabilities
vendor_ubuntu·2013-10-01·CVSS 4.3
CVE-2013-2099 [MEDIUM] Python 2.7 vulnerabilities
Title: Python 2.7 vulnerabilities
Summary: Several security issues were fixed in Python.
Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service. This
issue only affected Ubuntu 13.04. (CVE-2013-2099)
Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python 3.2 vulnerabilities
vendor_ubuntu·2013-10-01·CVSS 4.3
CVE-2013-2099 [MEDIUM] Python 3.2 vulnerabilities
Title: Python 3.2 vulnerabilities
Summary: Several security issues were fixed in Python.
Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service.
(CVE-2013-2099)
Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns
vendor_redhat·2013-05-15·CVSS 4.3
CVE-2013-2099 [MEDIUM] CWE-407 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns
python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
A denial of service flaw was found in the way Python's SSL module implementation performed matching of certain certificate names. A remote attacker able to obtain a valid certificate that contained multiple wildcard characters could use this flaw to issue a request to validate such a certificate, resulting in excessive consumption of CPU.
Stateme
Debian
CVE-2013-2099: bzr - Algorithmic complexity vulnerability in the ssl.match_hostname function in Pytho...
vendor_debian·2013·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099: bzr - Algorithmic complexity vulnerability in the ssl.match_hostname function in Pytho...
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
Scope: local
bookworm: resolved (fixed in 2.6.0~bzr6574-1)
bullseye: resolved (fixed in 2.6.0~bzr6574-1)
trixie: resolved (fixed in 2.6.0~bzr6574-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
bugzilla·2016-02-03·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
+++ This bug was initially created as a clone of Bug #1231231 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
bugzilla·2016-02-03·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
+++ This bug was initially created as a clone of Bug #1231231 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
bugzilla·2016-02-03·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
+++ This bug was initially created as a clone of Bug #1231231 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
bugzilla·2015-06-12·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [epel-all]
bugzilla·2015-06-12·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [epel-all]
CVE-2013-2099 CVE-2013-7440 python-pymongo: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2013-2099 CVE-2013-7440 python-distlib: various flaws [fedora-all]
bugzilla·2015-06-11·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 CVE-2013-7440 python-distlib: various flaws [fedora-all]
CVE-2013-2099 CVE-2013-7440 python-distlib: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2013-7440 python: wildcard matching rules do not follow RFC 6125
bugzilla·2015-05-26·CVSS 4.3
CVE-2013-7440 [MEDIUM] CVE-2013-7440 python: wildcard matching rules do not follow RFC 6125
CVE-2013-7440 python: wildcard matching rules do not follow RFC 6125
It was found that Python's SSL hostname matching rules did not conform to RFC 6125 when the hostname included wildcards.
Upstream issue:
https://bugs.python.org/issue17997#msg194950
CVE assignment:
http://seclists.org/oss-sec/2015/q2/523
Upstream patch:
https://hg.python.org/cpython/rev/10d0edadbcdd
Discussion:
This was fixed upstream in Python 3.3.3, and also in backports.ssl_match_hostname 3.4.0.2:
https://pypi.python.org/pypi/backports.ssl_match_hostname/3.4.0.2
Corrected version was also added to Python 2.7.9. Python 2.7 versions before 2.7.9 did not include match_hostname() and hence were not affected.
---
The backports.ssl_match_hostname is bundled with urllib3 upstream sources. Additionally, urllib3 is
Bugzilla
CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
bugzilla·2013-06-03·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes f
Bugzilla
CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-all]
bugzilla·2013-06-03·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-all]
CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi note
Bugzilla
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-2098 [MEDIUM] CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-2098 [MEDIUM] CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-2098 [MEDIUM] CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-2098 [MEDIUM] CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-2098 [MEDIUM] CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-2098 [MEDIUM] CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
bugzilla·2013-05-22·CVSS 4.3
CVE-2013-2098 [MEDIUM] CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2013-2099 python3 (ssl module): Denial of service when matching certificate name with many '*' wildcard characters [fedora-all]
bugzilla·2013-05-15·CVSS 4.3
CVE-2013-2099 [MEDIUM] CVE-2013-2099 python3 (ssl module): Denial of service when matching certificate name with many '*' wildcard characters [fedora-all]
CVE-2013-2099 python3 (ssl module): Denial of service when matching certificate name with many '*' wildcard characters [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi no
Bugzilla
python-pip: insecure temporary directory usage [epel-all]
bugzilla·2013-03-20
[LOW] python-pip: insecure temporary directory usage [epel-all]
python-pip: insecure temporary directory usage [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple s
http://bugs.python.org/issue17980http://rhn.redhat.com/errata/RHSA-2014-1690.htmlhttp://secunia.com/advisories/55107http://secunia.com/advisories/55116http://www.openwall.com/lists/oss-security/2013/05/16/6http://www.ubuntu.com/usn/USN-1983-1http://www.ubuntu.com/usn/USN-1984-1http://www.ubuntu.com/usn/USN-1985-1https://access.redhat.com/errata/RHSA-2016:1166https://bugzilla.redhat.com/show_bug.cgi?id=963260http://bugs.python.org/issue17980http://rhn.redhat.com/errata/RHSA-2014-1690.htmlhttp://secunia.com/advisories/55107http://secunia.com/advisories/55116http://www.openwall.com/lists/oss-security/2013/05/16/6http://www.ubuntu.com/usn/USN-1983-1http://www.ubuntu.com/usn/USN-1984-1http://www.ubuntu.com/usn/USN-1985-1https://access.redhat.com/errata/RHSA-2016:1166https://bugzilla.redhat.com/show_bug.cgi?id=963260
2013-10-09
Published