cbcvebase.
CVE-2013-2099
published 2013-10-09

CVE-2013-2099: Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of…

PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.86%
91.0th percentile
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianbzr< bzr 2.6.0~bzr6574-1 (bookworm)bzr 2.6.0~bzr6574-1 (bookworm)
debianlinkchecker< bzr 2.6.0~bzr6574-1 (bookworm)bzr 2.6.0~bzr6574-1 (bookworm)
debianpython-tornado< bzr 2.6.0~bzr6574-1 (bookworm)bzr 2.6.0~bzr6574-1 (bookworm)
debianpython-urllib3< bzr 2.6.0~bzr6574-1 (bookworm)bzr 2.6.0~bzr6574-1 (bookworm)
debianpython2.7< bzr 2.6.0~bzr6574-1 (bookworm)bzr 2.6.0~bzr6574-1 (bookworm)
pythonpython
pythonpython
pythonpython
pythonpython
pythonpython
pythonpython
pythonpython
pythonpython
pythonpython

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.