CVE-2014-9365
published 2014-12-12CVE-2014-9365: The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when…
PriorityP430medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
3.27%
87.0th percentile
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | python2.7 | < python2.7 2.7.9-1 (bullseye) | python2.7 2.7.9-1 (bullseye) |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python: failure to validate certificates in the HTTP client with TLS (PEP 476)
vendor_redhat·2014-12-11·CVSS 5.8
CVE-2014-9365 [MEDIUM] CWE-345 python: failure to validate certificates in the HTTP client with TLS (PEP 476)
python: failure to validate certificates in the HTTP client with TLS (PEP 476)
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
The Python standard library HTTP client modules (such as httplib or urllib) did not perform verification of TLS/SSL certificates when connecting to HTTPS servers. A man-in-the-middle attacker could use this flaw to hijack connections and ea
Debian
CVE-2014-9365: python2.7 - The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib ...
vendor_debian·2014·CVSS 5.8
CVE-2014-9365 [MEDIUM] CVE-2014-9365: python2.7 - The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib ...
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Scope: local
bullseye: resolved (fixed in 2.7.9-1)
Apple
CVE-2014-9365: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 5.8
CVE-2014-9365 [MEDIUM] CVE-2014-9365: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-9365
Component: CVE-2014-9365
GHSA
GHSA-fj2p-9cqv-m944: The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2
ghsa_unreviewed·2022-05-13
CVE-2014-9365 [MEDIUM] GHSA-fj2p-9cqv-m944: The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
OSV
CVE-2014-9365: The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2
osv·2014-12-12·CVSS 5.8
CVE-2014-9365 [MEDIUM] CVE-2014-9365: The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
No detection rules found.
No public exploits indexed.
http://bugs.python.org/issue22417http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://www.openwall.com/lists/oss-security/2014/12/11/1http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/71639https://access.redhat.com/errata/RHSA-2016:1166https://access.redhat.com/errata/RHSA-2017:1162https://access.redhat.com/errata/RHSA-2017:1868https://security.gentoo.org/glsa/201503-10https://support.apple.com/kb/HT205031https://www.python.org/dev/peps/pep-0476/https://www.python.org/downloads/release/python-279/http://bugs.python.org/issue22417http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://www.openwall.com/lists/oss-security/2014/12/11/1http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/71639https://access.redhat.com/errata/RHSA-2016:1166https://access.redhat.com/errata/RHSA-2017:1162https://access.redhat.com/errata/RHSA-2017:1868https://security.gentoo.org/glsa/201503-10https://support.apple.com/kb/HT205031https://www.python.org/dev/peps/pep-0476/https://www.python.org/downloads/release/python-279/
2014-12-12
Published