Improper resource allocation In python-urllib3
Description
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 1.6-2 | ||
debian 11 | 8.5-1 | ||
debian 11 | 2.7.5-5 | ||
debian 11 | 2.4.1-3 | ||
debian 11 | 2.6.0~bzr6574-1 | ||
debian 11 | 1.6-2 | ||
debian 12 | 2.4.1-3 | ||
debian 12 | 2.6.0~bzr6574-1 | ||
debian 12 | 8.5-1 | ||
debian 13 | 2.4.1-3 |
1-10 of 18
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1.