CVE-2013-4238
published 2013-08-18CVE-2013-4238: The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject…
PriorityP429medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.35%
91.7th percentile
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | python2.7 | < python2.7 2.7.5-8 (bullseye) | python2.7 2.7.5-8 (bullseye) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vSphere product updates address security vulnerabilities
vendor_vmware·2014-12-04·CVSS 4.3
CVE-2013-1752 [MEDIUM] VMware vSphere product updates address security vulnerabilities
VMSA-2014-0012: VMware vSphere product updates address security vulnerabilities
a. VMware vCSA cross-site scripting vulnerability VMware vCenter Server Appliance (vCSA) contains a vulnerability that may allow for Cross Site Scripting. Exploitation of this vulnerability in vCenter Server requires tricking a user to click on a malicious link or to open a malicious web page. VMware would like to thank Tanya Secker of Trustwave SpiderLabs for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-3797 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Pro
Ubuntu
Python 2.6 vulnerability
vendor_ubuntu·2013-10-01
CVE-2013-4238 Python 2.6 vulnerability
Title: Python 2.6 vulnerability
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python 3.3 vulnerabilities
vendor_ubuntu·2013-10-01·CVSS 4.3
CVE-2013-2099 [MEDIUM] Python 3.3 vulnerabilities
Title: Python 3.3 vulnerabilities
Summary: Several security issues were fixed in Python.
Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service.
(CVE-2013-2099)
Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python 2.7 vulnerabilities
vendor_ubuntu·2013-10-01·CVSS 4.3
CVE-2013-2099 [MEDIUM] Python 2.7 vulnerabilities
Title: Python 2.7 vulnerabilities
Summary: Several security issues were fixed in Python.
Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service. This
issue only affected Ubuntu 13.04. (CVE-2013-2099)
Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python 3.2 vulnerabilities
vendor_ubuntu·2013-10-01·CVSS 4.3
CVE-2013-2099 [MEDIUM] Python 3.2 vulnerabilities
Title: Python 3.2 vulnerabilities
Summary: Several security issues were fixed in Python.
Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service.
(CVE-2013-2099)
Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python: hostname check bypassing vulnerability in SSL module
vendor_redhat·2013-08-12·CVSS 5.9
CVE-2013-4238 [MEDIUM] python: hostname check bypassing vulnerability in SSL module
python: hostname check bypassing vulnerability in SSL module
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue does not affect the version of python as shipped with Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.
Package: python (Red Hat Enterprise Linux 5) - Not affected
Package: python (Red Hat Enterprise Linux 7) - Not affected
P
Debian
CVE-2013-4238: python2.7 - The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does...
vendor_debian·2013·CVSS 5.9
CVE-2013-4238 [MEDIUM] CVE-2013-4238: python2.7 - The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does...
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Scope: local
bullseye: resolved (fixed in 2.7.5-8)
GHSA
GHSA-vp8q-678w-8xq9: The ssl
ghsa_unreviewed·2022-05-13·CVSS 5.9
CVE-2013-4238 [MEDIUM] CWE-20 GHSA-vp8q-678w-8xq9: The ssl
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
OSV
CVE-2013-4238: The ssl
osv·2013-08-18·CVSS 5.9
CVE-2013-4238 [MEDIUM] CVE-2013-4238: The ssl
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4238 python26: python: hostname check bypassing vulnerability in SSL module [epel-5]
bugzilla·2013-08-20·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python26: python: hostname check bypassing vulnerability in SSL module [epel-5]
CVE-2013-4238 python26: python: hostname check bypassing vulnerability in SSL module [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5
Bugzilla
CVE-2013-4238 python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-19·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2013-4248 php: hostname check bypassing vulnerability in SSL client
bugzilla·2013-08-14·CVSS 6.8
CVE-2013-4248 [MEDIUM] CVE-2013-4248 php: hostname check bypassing vulnerability in SSL client
CVE-2013-4248 php: hostname check bypassing vulnerability in SSL client
Similar to Ruby (CVE-2013-4073) and Python (CVE-2013-4238), PHP also suffers from how it checked the hostname's identity when handling certificates that contain hostnames with NULL bytes. An attacker could potentially exploit this flaw to conduct man-in-the-middle attacks to spoof SSL servers. Note that to exploit this issue, an attacker would need to obtain a carefully-crafted certificate signed by an authority that the client trusts.
This has been corrected in upstream git:
http://git.php.net/?p=php-src.git;a=commit;h=dcea4ec698dcae39b7bba6f6aa08933cbfee6755
http://git.php.net/?p=php-src.git;a=commit;h=2874696a5a8d46639d261571f915c493cd875897
While PHP referenced the Ruby CVE, one has not yet been assigned to PHP
Bugzilla
CVE-2013-4238 python-requests: python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-requests: python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 python-requests: python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-4238 python-backports-ssl_match_hostname: python: hostname check bypassing vulnerability in SSL module [epel-6]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-backports-ssl_match_hostname: python: hostname check bypassing vulnerability in SSL module [epel-6]
CVE-2013-4238 python-backports-ssl_match_hostname: python: hostname check bypassing vulnerability in SSL module [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes fi
Bugzilla
CVE-2013-4238 python-pip: python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-pip: python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 python-pip: python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pleas
Bugzilla
CVE-2013-4238 python-tornado: python: hostname check bypassing vulnerability in SSL module [epel-6]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-tornado: python: hostname check bypassing vulnerability in SSL module [epel-6]
CVE-2013-4238 python-tornado: python: hostname check bypassing vulnerability in SSL module [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-4238 bzr: python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 bzr: python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 bzr: python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-4238 zeroinstall-injector: python: hostname check bypassing vulnerability in SSL module [epel-6]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 zeroinstall-injector: python: hostname check bypassing vulnerability in SSL module [epel-6]
CVE-2013-4238 zeroinstall-injector: python: hostname check bypassing vulnerability in SSL module [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availa
Bugzilla
CVE-2013-4238 python3: python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python3: python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 python3: python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
Bugzilla
CVE-2013-4238 python: hostname check bypassing vulnerability in SSL module
bugzilla·2013-08-13·CVSS 6.8
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python: hostname check bypassing vulnerability in SSL module
CVE-2013-4238 python: hostname check bypassing vulnerability in SSL module
A flaw was found in the way ssl.match_hostname() from the Python SSL module checked the hostname's identity when handling certificates that contain hostnames with NULL bytes. An attacker could potentially exploit this flaw to conduct man-in-the-middle attacks to spoof SSL servers. Note that to exploit this issue, an attacker would need to obtain a carefully-crafted certificate signed by an authority that the client trusts.
References:
http://bugs.python.org/issue18709
http://bugs.python.org/file31241/CVE-2013-4073_py34.patch
http://bugs.python.org/file31242/CVE-2013-4073_py33.patch
http://bugs.python.org/file31243/CVE-2013-4073_py27.patch
Discussion:
This flaw is similar to CVE-2013-4073, which affected Ruby: h
Bugzilla
CVE-2013-4238 python-requests: python: hostname check bypassing vulnerability in SSL module [epel-6]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-requests: python: hostname check bypassing vulnerability in SSL module [epel-6]
CVE-2013-4238 python-requests: python: hostname check bypassing vulnerability in SSL module [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-4238 zeroinstall-injector: python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 zeroinstall-injector: python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 zeroinstall-injector: python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2013-4238 python-backports-ssl_match_hostname: python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-backports-ssl_match_hostname: python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 python-backports-ssl_match_hostname: python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes fie
Bugzilla
CVE-2013-4238 python-pip: python: hostname check bypassing vulnerability in SSL module [epel-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-pip: python: hostname check bypassing vulnerability in SSL module [epel-all]
CVE-2013-4238 python-pip: python: hostname check bypassing vulnerability in SSL module [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pl
Bugzilla
CVE-2013-4238 python-tornado: python: hostname check bypassing vulnerability in SSL module [fedora-all]
bugzilla·2013-08-13·CVSS 4.3
CVE-2013-4238 [MEDIUM] CVE-2013-4238 python-tornado: python: hostname check bypassing vulnerability in SSL module [fedora-all]
CVE-2013-4238 python-tornado: python: hostname check bypassing vulnerability in SSL module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
P
http://bugs.python.org/issue18709http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00026.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00027.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1582.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://www.debian.org/security/2014/dsa-2880http://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.ubuntu.com/usn/USN-1982-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=996381http://bugs.python.org/issue18709http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00026.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00027.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1582.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://www.debian.org/security/2014/dsa-2880http://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.ubuntu.com/usn/USN-1982-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=996381
2013-08-18
Published