Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
BID:71639
Info
Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 71639 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-9365 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2014 12:00AM |
| Updated: | Nov 03 2015 07:02PM |
| Credit: | Alex Gaynor |
| Vulnerable: |
Python Software Foundation Python 3.2.2 Python Software Foundation Python 3.1.1 Python Software Foundation Python 3.0.1 Python Software Foundation Python 2.7.2 Python Software Foundation Python 2.6.5 Python Software Foundation Python 2.6.2 Python Software Foundation Python 2.5.6 Python Software Foundation Python 2.5.5 Python Software Foundation Python 2.5.3 Python Software Foundation Python 2.5.2 Python Software Foundation Python 2.5.1 Python Software Foundation Python 2.4.5 Python Software Foundation Python 2.4.4 Python Software Foundation Python 2.4.3 Python Software Foundation Python 2.4.2 Python Software Foundation Python 2.4.1 Python Software Foundation Python 2.4 Python Software Foundation Python 2.3.6 Python Software Foundation Python 2.3.5 Python Software Foundation Python 2.3.4 Python Software Foundation Python 2.3.3 Python Software Foundation Python 2.3.2 Python Software Foundation Python 2.3.1 Python Software Foundation Python 2.3 Python Software Foundation Python 2.2.3 Python Software Foundation Python 2.2.2 Python Software Foundation Python 2.2.1 Python Software Foundation Python 2.2 Python Software Foundation Python 2.1.3 Python Software Foundation Python 2.1.2 Python Software Foundation Python 2.1.1 Python Software Foundation Python 2.1 Python Software Foundation Python 2.0.1 Python Software Foundation Python 2.0 Python Software Foundation Python 3.1.2 Python Software Foundation Python 3.1 Python Software Foundation Python 2.7 Python Software Foundation Python 2.6 Python Software Foundation Python 2.5 |
| Not Vulnerable: | |
Discussion
Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
Python is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Python is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Python CVE-2014-9365 TLS Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.