Asymmetric denial of service In python
Description
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.19 | 3.6.8-r1 | ||
alpine v3.11 | 2.7.15-r3 | ||
alpine v3.20 | 3.6.8-r1 | ||
alpine v3.9 | 2.7.15-r3 | ||
alpine v3.10 | 3.6.8-r1 | ||
alpine v3.14 | 3.6.8-r1 | ||
alpine v3.15 | 3.6.8-r1 | ||
alpine v3.17 | 3.6.8-r1 | ||
alpine v3.22 | 3.6.8-r1 | ||
debian 11 | 2.7.15-6 |
1-10 of 26
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.
References
1. 2.