CVE-2019-5010
published 2019-10-31CVE-2019-5010: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
21.44%
97.3th percentile
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | python2.7 | < python2.7 2.7.15-6 (bullseye) | python2.7 2.7.15-6 (bullseye) |
| opensuse | leap | — | — |
| python | python | — | — |
| python | python | >= 2.7.0 < 2.7.16 | 2.7.16 |
| python | python | >= 3.4.0 < 3.4.10 | 3.4.10 |
| python | python | >= 3.5.0 < 3.5.7 | 3.5.7 |
| python | python | >= 3.6.0 < 3.6.9 | 3.6.9 |
| python | python | >= 3.7.0 < 3.7.3 | 3.7.3 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-jj99-2g8j-7j25: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python
ghsa_unreviewed·2022-05-24
CVE-2019-5010 [HIGH] CWE-476 GHSA-jj99-2g8j-7j25: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
OSV
CVE-2019-5010: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python
osv·2019-10-31·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
OSV
python2.7, python3.4 vulnerabilities
osv·2019-09-10·CVSS 7.5
CVE-2018-20406 [HIGH] python2.7, python3.4 vulnerabilities
python2.7, python3.4 vulnerabilities
USN-4127-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 14.04 ESM. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain
OSV
python2.7, python3.5, python3.6, python3.7 vulnerabilities
osv·2019-09-09·CVSS 7.5
CVE-2018-20406 [HIGH] python2.7, python3.5, python3.6, python3.7 vulnerabilities
python2.7, python3.5, python3.6, python3.7 vulnerabilities
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2019-9636,
CVE-2019-10160)
Colin Read and Nicolas Edet discovered that Python incorrectly handled
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
Ubuntu
Python vulnerabilities
vendor_ubuntu·2019-09-10·CVSS 7.5
CVE-2018-20406 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
USN-4127-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 14.04 ESM. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An
Ubuntu
Python vulnerabilities
vendor_ubuntu·2019-09-09·CVSS 7.5
CVE-2018-20406 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2019-9636,
CVE-2019-10160)
Colin Read and Nicolas Edet discovered that
Red Hat
python: NULL pointer dereference using a specially crafted X509 certificate
vendor_redhat·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CWE-476 python: NULL pointer dereference using a specially crafted X509 certificate
python: NULL pointer dereference using a specially crafted X509 certificate
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
A null pointer dereference vulnerability was found in the certificate parsing code in Python. This causes a denial of service to applications when parsing specially crafted certificates. This vulnerability is unlikely to be triggered if application enables SSL/TLS certificate validation and accepts certificates only from trusted root certificate authorities.
Statement: This issu
Debian
CVE-2019-5010: python2.7 - An exploitable denial-of-service vulnerability exists in the X509 certificate pa...
vendor_debian·2019·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010: python2.7 - An exploitable denial-of-service vulnerability exists in the X509 certificate pa...
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
Scope: local
bullseye: resolved (fixed in 2.7.15-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5010 python34: python: NULL pointer dereference using a specially crafted X509 certificate [epel-all]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python34: python: NULL pointer dereference using a specially crafted X509 certificate [epel-all]
CVE-2019-5010 python34: python: NULL pointer dereference using a specially crafted X509 certificate [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2019-5010 python3: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python3: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
CVE-2019-5010 python3: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2019-5010 python: NULL pointer dereference using a specially crafted X509 certificate
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python: NULL pointer dereference using a specially crafted X509 certificate
CVE-2019-5010 python: NULL pointer dereference using a specially crafted X509 certificate
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.7.2. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
References:
https://bugs.python.org/issue35746
Upstream Patch:
https://github.com/python/cpython/pull/11569
Discussion:
Created python3 tracking bugs for this issue:
Affects: fedora-all [bug 1666522]
Created python33 tracking bugs for this issue:
Affects: fedora-28 [bug 1666524]
Created python34 tracking bugs for this issue:
Affects: epel-all [bug 1666526
Bugzilla
CVE-2019-5010 python34: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python34: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
CVE-2019-5010 python34: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-5010 python36: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-29]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python36: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-29]
CVE-2019-5010 python36: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use th
Bugzilla
CVE-2019-5010 python37: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-28]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python37: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-28]
CVE-2019-5010 python37: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use th
Bugzilla
CVE-2019-5010 python33: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-28]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python33: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-28]
CVE-2019-5010 python33: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use th
Bugzilla
CVE-2019-5010 python35: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python35: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
CVE-2019-5010 python35: python: NULL pointer dereference using a specially crafted X509 certificate [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-5010 python36: python: NULL pointer dereference using a specially crafted X509 certificate [epel-7]
bugzilla·2019-01-15·CVSS 7.5
CVE-2019-5010 [HIGH] CVE-2019-5010 python36: python: NULL pointer dereference using a specially crafted X509 certificate [epel-7]
CVE-2019-5010 python36: python: NULL pointer dereference using a specially crafted X509 certificate [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the foll
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttps://access.redhat.com/errata/RHSA-2019:3520https://access.redhat.com/errata/RHSA-2019:3725https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/07/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00034.htmlhttps://security.gentoo.org/glsa/202003-26https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttps://access.redhat.com/errata/RHSA-2019:3520https://access.redhat.com/errata/RHSA-2019:3725https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/07/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00034.htmlhttps://security.gentoo.org/glsa/202003-26https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758
2019-10-31
Published