CVE-2013-2191
published 2014-02-08CVE-2013-2191: python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.89%
55.3th percentile
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| python_bugzilla_project | python-bugzilla | <= 0.8.0 | — |
| python_bugzilla_project | python-bugzilla | — | — |
| python_bugzilla_project | python-bugzilla | — | — |
| python_bugzilla_project | python-bugzilla | — | — |
| python_bugzilla_project | python-bugzilla | — | — |
| python_bugzilla_project | python-bugzilla | >= 0 < 0.9.0 | 0.9.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python-bugzilla has improper validation of X.509 certificates
osv·2022-05-14
CVE-2013-2191 [HIGH] python-bugzilla has improper validation of X.509 certificates
python-bugzilla has improper validation of X.509 certificates
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
GHSA
python-bugzilla has improper validation of X.509 certificates
ghsa·2022-05-14
CVE-2013-2191 [HIGH] CWE-20 python-bugzilla has improper validation of X.509 certificates
python-bugzilla has improper validation of X.509 certificates
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
OSV
CVE-2013-2191: python-bugzilla before 0
osv·2014-02-08
CVE-2013-2191 CVE-2013-2191: python-bugzilla before 0
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0462 OpenJDK: libjpeg: uninitialized memory read information leak (AWT, 8029760)
bugzilla·2014-06-09·CVSS 5.0
CVE-2014-0462 [MEDIUM] CVE-2014-0462 OpenJDK: libjpeg: uninitialized memory read information leak (AWT, 8029760)
CVE-2014-0462 OpenJDK: libjpeg: uninitialized memory read information leak (AWT, 8029760)
The CVE id CVE-2014-0462 was assigned to the following issue:
Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-2405.
References:
http://www.debian.org/security/2014/dsa-2912
http://www.ubuntu.com/usn/USN-2191-1
http://secunia.com/advisories/58415
Discussion:
This CVE id was assigned incorrectly as a duplicate of libjpeg CVE-2013-6629 (see bug 1031734) for a bundled copy of the libjpeg code used in the OpenJDK sources. Incorrect assignment of the id was identified before the new releases were announced, so the id did not appear in those announcements. The id was b
Bugzilla
CVE-2014-2405 OpenJDK: libpng unhandled zero-length PLTE chunk or NULL palette (AWT, 8031352)
bugzilla·2014-06-09·CVSS 6.5
CVE-2014-2405 [MEDIUM] CVE-2014-2405 OpenJDK: libpng unhandled zero-length PLTE chunk or NULL palette (AWT, 8031352)
CVE-2014-2405 OpenJDK: libpng unhandled zero-length PLTE chunk or NULL palette (AWT, 8031352)
The CVE id CVE-2014-2405 was assigned to the following issue:
Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-0462.
References:
http://www.debian.org/security/2014/dsa-2912
http://www.ubuntu.com/usn/USN-2191-1
http://secunia.com/advisories/58415
Discussion:
This CVE id was assigned incorrectly as a duplicate of libpng CVE-2013-6954 (see bug 1045561) for a bundled copy of the ligpng code used in the OpenJDK sources. Incorrect assignment of the id was identified before the new releases were announced, so the id did not appear in those announcements. The id was
Bugzilla
CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate [fedora-all]
bugzilla·2013-06-19·CVSS 4.3
CVE-2013-2191 [MEDIUM] CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate [fedora-all]
CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate [epel-all]
bugzilla·2013-06-19·CVSS 4.3
CVE-2013-2191 [MEDIUM] CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate [epel-all]
CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: t
Bugzilla
CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate
bugzilla·2013-04-12·CVSS 4.3
CVE-2013-2191 [MEDIUM] CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate
CVE-2013-2191 python-bugzilla: Does not verify Bugzilla server certificate
python-bugzilla uses the default xmlrpclib transports, which are based on classes in httplib which do not perform server certificate checking. As a result, man-in-the-middle attacks on the HTTPS connection are possible.
Discussion:
It was found that python-bugzilla, a Python library for interacting with Bugzilla instances over XML-RPC functionality, did not perform X.509 certificate verification when using secured SSL connection. A man-in-the-middle (MiTM) attacker could use this flaw to spoof Bugzilla server via an arbitrary certificate.
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
---
The CVE identifier of CVE-2013-2191 has been assigned to this issue.
---
This issue af
http://lists.opensuse.org/opensuse-updates/2013-07/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00026.htmlhttp://www.openwall.com/lists/oss-security/2013/06/19/6https://bugzilla.redhat.com/show_bug.cgi?id=951594https://git.fedorahosted.org/cgit/python-bugzilla.git/commit/?id=a782282ee479ba4cc1b8b1d89700ac630ba83eefhttps://lists.fedorahosted.org/pipermail/python-bugzilla/2013-June/000104.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00026.htmlhttp://www.openwall.com/lists/oss-security/2013/06/19/6https://bugzilla.redhat.com/show_bug.cgi?id=951594https://git.fedorahosted.org/cgit/python-bugzilla.git/commit/?id=a782282ee479ba4cc1b8b1d89700ac630ba83eefhttps://lists.fedorahosted.org/pipermail/python-bugzilla/2013-June/000104.html
2014-02-08
Published