QID 998083
QID 998083: Python (Pip) Security Update for dnspython (GHSA-3rq5-2g8h-59hc)
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3rq5-2g8h-59hc for updates and patch information.
Vendor References
- GHSA-3rq5-2g8h-59hc -
github.com/advisories/GHSA-3rq5-2g8h-59hc
CVEs related to QID 998083
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3rq5-2g8h-59hc | dnspython |
|