CVE-2013-4238
Publication date 17 August 2013
Last updated 24 July 2024
Ubuntu priority
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Status
Package | Ubuntu Release | Status |
---|---|---|
python2.6 | ||
python2.7 | ||
python3.1 | ||
python3.2 | ||
python3.3 | ||
Notes
Patch details
Package | Patch details |
---|---|
python2.6 | |
python2.7 | |
python3.3 |
|
References
Related Ubuntu Security Notices (USN)
- USN-1985-1
- Python 3.3 vulnerabilities
- 1 October 2013
- USN-1984-1
- Python 3.2 vulnerabilities
- 1 October 2013
- USN-1983-1
- Python 2.7 vulnerabilities
- 1 October 2013
- USN-1982-1
- Python 2.6 vulnerability
- 1 October 2013