{"api_version":"1","generated_at":"2026-07-23T08:16:07+00:00","cve":"CVE-2010-3492","urls":{"html":"https://cve.report/CVE-2010-3492","api":"https://cve.report/api/cve/CVE-2010-3492.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-3492","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-3492"},"summary":{"title":"CVE-2010-3492","description":"The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-10-19 20:00:04","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2010/09/22/3","name":"http://www.openwall.com/lists/oss-security/2010/09/22/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE Request -- Python -- accept() implementation\n in async core is broken => more subcases","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2010/09/11/2","name":"http://www.openwall.com/lists/oss-security/2010/09/11/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE Request -- Python -- accept() implementation\n in async core is broken => more subcases","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.python.org/issue6706","name":"http://bugs.python.org/issue6706","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Issue 6706: asyncore's accept() is broken - Python tracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2010:215 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2010/09/24/3","name":"http://www.openwall.com/lists/oss-security/2010/09/24/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE Request -- Python -- accept() implementation\n in async core is broken => more subcases","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:216","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:216","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2010:216 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12111","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12111","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2010/09/09/6","name":"http://www.openwall.com/lists/oss-security/2010/09/09/6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE Request -- Python -- accept() implementation in async core is\n broken => more subcases","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-3492","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-3492","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"3492","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"python","cpe5":"python","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3492","vulnerable":"1","versionEndIncluding":"2.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"python","cpe5":"python","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:11:44.327Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[oss-security] 20100910 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2010/09/11/2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.python.org/issue6706"},{"name":"MDVSA-2010:216","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:216"},{"name":"oval:org.mitre.oval:def:12111","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12111"},{"name":"[oss-security] 20100924 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2010/09/24/3"},{"name":"[oss-security] 20100922 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2010/09/22/3"},{"name":"[oss-security] 20100909 CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2010/09/09/6"},{"name":"MDVSA-2010:215","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-09-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"[oss-security] 20100910 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2010/09/11/2"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.python.org/issue6706"},{"name":"MDVSA-2010:216","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:216"},{"name":"oval:org.mitre.oval:def:12111","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12111"},{"name":"[oss-security] 20100924 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2010/09/24/3"},{"name":"[oss-security] 20100922 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2010/09/22/3"},{"name":"[oss-security] 20100909 CVE Request -- Python -- accept() implementation in async core is broken => more subcases","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2010/09/09/6"},{"name":"MDVSA-2010:215","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-3492","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[oss-security] 20100910 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2010/09/11/2"},{"name":"http://bugs.python.org/issue6706","refsource":"CONFIRM","url":"http://bugs.python.org/issue6706"},{"name":"MDVSA-2010:216","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:216"},{"name":"oval:org.mitre.oval:def:12111","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12111"},{"name":"[oss-security] 20100924 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2010/09/24/3"},{"name":"[oss-security] 20100922 Re: CVE Request -- Python -- accept() implementation in async core is broken => more subcases","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2010/09/22/3"},{"name":"[oss-security] 20100909 CVE Request -- Python -- accept() implementation in async core is broken => more subcases","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2010/09/09/6"},{"name":"MDVSA-2010:215","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-3492","datePublished":"2010-10-19T19:00:00.000Z","dateReserved":"2010-09-24T00:00:00.000Z","dateUpdated":"2024-08-07T03:11:44.327Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-10-19 20:00:04","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","versionEndIncluding":"2.7","matchCriteriaId":"5C7AE3F2-A21B-4F96-A7F5-6B105A8CE540"},{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"3.1.2","matchCriteriaId":"CF69B7D8-20B0-44E3-9AE8-BD29691EE13E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"3492","Ordinal":"1","Title":"CVE-2010-3492","CVE":"CVE-2010-3492","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"3492","Ordinal":"1","NoteData":"The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.","Type":"Description","Title":"CVE-2010-3492"},{"CveYear":"2010","CveId":"3492","Ordinal":"2","NoteData":"2010-10-19","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"3492","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}