Back to search
CVE-2013-2099
Published: Oct 9, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=963260
x_refsource_MISC
USN-1984-1
vendor-advisory
x_refsource_UBUNTU
55116
third-party-advisory
x_refsource_SECUNIA
RHSA-2016:1166
vendor-advisory
x_refsource_REDHAT
USN-1985-1
vendor-advisory
x_refsource_UBUNTU
http://bugs.python.org/issue17980
x_refsource_CONFIRM
55107
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:1690
vendor-advisory
x_refsource_REDHAT
USN-1983-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now