python-httplib2 CVE-2013-2037 SSL Certificate Validation Security Bypass Vulnerability
BID:52179
Info
python-httplib2 CVE-2013-2037 SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 52179 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2037 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2012 12:00AM |
| Updated: | Dec 07 2015 10:19PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 python httplib2 0.6 |
| Not Vulnerable: |
python httplib2 0.7 |
Discussion
python-httplib2 CVE-2013-2037 SSL Certificate Validation Security Bypass Vulnerability
python-httplib2 is prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
python-httplib2 versions prior to 0.7.0 are vulnerable.
python-httplib2 is prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
python-httplib2 versions prior to 0.7.0 are vulnerable.
Exploit / POC
python-httplib2 CVE-2013-2037 SSL Certificate Validation Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
python-httplib2 CVE-2013-2037 SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
python-httplib2 CVE-2013-2037 SSL Certificate Validation Security Bypass Vulnerability
References:
References: