CVE-2014-9365
Summary
| CVE | CVE-2014-9365 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-12 11:59:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. |
Risk And Classification
Primary CVSS: v2.0 5.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Python | Python | 2.0 | All | All | All |
| Application | Python | Python | 2.0.1 | All | All | All |
| Application | Python | Python | 2.1 | All | All | All |
| Application | Python | Python | 2.1.1 | All | All | All |
| Application | Python | Python | 2.1.2 | All | All | All |
| Application | Python | Python | 2.1.3 | All | All | All |
| Application | Python | Python | 2.2 | All | All | All |
| Application | Python | Python | 2.2.1 | All | All | All |
| Application | Python | Python | 2.2.2 | All | All | All |
| Application | Python | Python | 2.2.3 | All | All | All |
| Application | Python | Python | 2.3.1 | All | All | All |
| Application | Python | Python | 2.3.2 | All | All | All |
| Application | Python | Python | 2.3.3 | All | All | All |
| Application | Python | Python | 2.3.4 | All | All | All |
| Application | Python | Python | 2.3.5 | All | All | All |
| Application | Python | Python | 2.3.7 | All | All | All |
| Application | Python | Python | 2.4.1 | All | All | All |
| Application | Python | Python | 2.4.2 | All | All | All |
| Application | Python | Python | 2.4.3 | All | All | All |
| Application | Python | Python | 2.4.4 | All | All | All |
| Application | Python | Python | 2.4.6 | All | All | All |
| Application | Python | Python | 2.5.1 | All | All | All |
| Application | Python | Python | 2.5.150 | All | All | All |
| Application | Python | Python | 2.5.2 | All | All | All |
| Application | Python | Python | 2.5.3 | All | All | All |
| Application | Python | Python | 2.5.4 | All | All | All |
| Application | Python | Python | 2.5.6 | All | All | All |
| Application | Python | Python | 2.6.1 | All | All | All |
| Application | Python | Python | 2.6.2 | All | All | All |
| Application | Python | Python | 2.6.2150 | All | All | All |
| Application | Python | Python | 2.6.3 | All | All | All |
| Application | Python | Python | 2.6.4 | All | All | All |
| Application | Python | Python | 2.6.5 | All | All | All |
| Application | Python | Python | 2.6.6 | All | All | All |
| Application | Python | Python | 2.6.6150 | All | All | All |
| Application | Python | Python | 2.6.7 | All | All | All |
| Application | Python | Python | 2.6.8 | All | All | All |
| Application | Python | Python | 2.7.1 | All | All | All |
| Application | Python | Python | 2.7.1 | rc1 | All | All |
| Application | Python | Python | 2.7.1150 | All | All | All |
| Application | Python | Python | 2.7.1150 | All | All | All |
| Application | Python | Python | 2.7.2 | rc1 | All | All |
| Application | Python | Python | 2.7.2150 | All | All | All |
| Application | Python | Python | 2.7.3 | All | All | All |
| Application | Python | Python | 2.7.4 | All | All | All |
| Application | Python | Python | 2.7.5 | All | All | All |
| Application | Python | Python | 2.7.6 | All | All | All |
| Application | Python | Python | 2.7.7 | All | All | All |
| Application | Python | Python | 2.7.8 | All | All | All |
| Application | Python | Python | 3.0 | All | All | All |
| Application | Python | Python | 3.0.1 | All | All | All |
| Application | Python | Python | 3.1 | All | All | All |
| Application | Python | Python | 3.1.1 | All | All | All |
| Application | Python | Python | 3.1.2 | All | All | All |
| Application | Python | Python | 3.1.2150 | All | All | All |
| Application | Python | Python | 3.1.3 | All | All | All |
| Application | Python | Python | 3.1.4 | All | All | All |
| Application | Python | Python | 3.1.5 | All | All | All |
| Application | Python | Python | 3.2 | All | All | All |
| Application | Python | Python | 3.2 | alpha | All | All |
| Application | Python | Python | 3.2.0 | All | All | All |
| Application | Python | Python | 3.2.1 | All | All | All |
| Application | Python | Python | 3.2.2 | All | All | All |
| Application | Python | Python | 3.2.2150 | All | All | All |
| Application | Python | Python | 3.2.3 | All | All | All |
| Application | Python | Python | 3.2.4 | All | All | All |
| Application | Python | Python | 3.2.5 | All | All | All |
| Application | Python | Python | 3.2.6 | All | All | All |
| Application | Python | Python | 3.3 | All | All | All |
| Application | Python | Python | 3.3 | beta2 | All | All |
| Application | Python | Python | 3.3.0 | All | All | All |
| Application | Python | Python | 3.3.1 | All | All | All |
| Application | Python | Python | 3.3.1 | rc1 | All | All |
| Application | Python | Python | 3.3.2 | All | All | All |
| Application | Python | Python | 3.3.3 | All | All | All |
| Application | Python | Python | 3.3.3 | rc1 | All | All |
| Application | Python | Python | 3.3.3 | rc2 | All | All |
| Application | Python | Python | 3.3.4 | All | All | All |
| Application | Python | Python | 3.3.4 | rc1 | All | All |
| Application | Python | Python | 3.3.5 | - | All | All |
| Application | Python | Python | 3.3.5 | rc1 | All | All |
| Application | Python | Python | 3.3.5 | rc2 | All | All |
| Application | Python | Python | 3.3.6 | rc1 | All | All |
| Application | Python | Python | 3.4 | alpha1 | All | All |
| Application | Python | Python | 3.4.0 | All | All | All |
| Application | Python | Python | 3.4.1 | All | All | All |
| Application | Python | Python | 3.4.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Python Release Python 2.7.9 | Python.org | af854a3a-2127-422b-91ae-364da2661108 | www.python.org | |
| Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update 2015-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| oss-security - CVE request: Python, standard library HTTP clients | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Oracle Bulletin Board Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Oracle Solaris Third Party Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| PEP 0476 -- Enabling certificate verification by default for stdlib http clients | Python.org | af854a3a-2127-422b-91ae-364da2661108 | www.python.org | Exploit, Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Issue 22417: PEP 476: verify HTTPS certificates by default - Python tracker | af854a3a-2127-422b-91ae-364da2661108 | bugs.python.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.