← Back

CVE-2013-7440

nvd nist
Published: Jun 7, 2016Modified: May 6, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected (26)

Products: Python: Python
1 product
Python
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.7.8
Configuration B
25 vulnerable
Vulnerable SoftwareAffected Versions
Python
Version 3.0.1
Version 3.0
Version 3.1.1
Version 3.1.2150
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1.5
Version 3.1
Version 3.2.0
Version 3.2.1
Version 3.2.2150
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2
Version 3.2 alpha
Version 3.3.0
Version 3.3.1
Version 3.3.1 rc1
Version 3.3.2
Version 3.3
Version 3.3 beta2

Related CWEs

References (14)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.