← Back

CVE-2010-3495

nvd nist
Published: Oct 19, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Race condition in ZEO/StorageServer.py in Zope Object Database (ZODB) before 3.10.0 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.

Affected (28)

Products: Zope: Zodb
1 product
Zodb
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Zope
Up to 3.9.7
Version 2.10.9
Version 2.11.4
Version 2.8.11
Version 2.9.11
Version 3.1.1
Version 3.1
Version 3.2.4
Version 3.2
Version 3.3.3
Version 3.3
Version 3.4.1
Version 3.4
Version 3.5
Version 3.6
Version 3.7
Version 3.8.0
Version 3.8.1
Version 3.8.2
Version 3.8.6
Version 3.8
Version 3.9.0
Version 3.9.0b1
Version 3.9.0b2
Version 3.9.0b3
Version 3.9.0b4
Version 3.9.0b5
Version 3.9.0c1

References (18)

Source: cve@mitre.org
Patch
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.