4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
7.3 High
AI Score
Confidence
High
0.115 Low
EPSS
Percentile
95.3%
Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492.
CPE | Name | Operator | Version |
---|---|---|---|
python:python | python | eq | 3.1 |
python:python | python | eq | 3.2 |
bugs.python.org/issue6706
bugs.python.org/issue9129
lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
secunia.com/advisories/43068
secunia.com/advisories/50858
secunia.com/advisories/51024
secunia.com/advisories/51040
svn.python.org/view/python/branches/py3k/Lib/smtpd.py?r1=84289&r2=84288&pathrev=84289
svn.python.org/view?view=rev&revision=84289
www.mandriva.com/security/advisories?name=MDVSA-2010:215
www.mandriva.com/security/advisories?name=MDVSA-2010:216
www.openwall.com/lists/oss-security/2010/09/09/6
www.openwall.com/lists/oss-security/2010/09/11/2
www.openwall.com/lists/oss-security/2010/09/22/3
www.openwall.com/lists/oss-security/2010/09/24/3
www.securityfocus.com/bid/44533
www.ubuntu.com/usn/USN-1596-1
www.ubuntu.com/usn/USN-1613-1
www.ubuntu.com/usn/USN-1613-2
www.vupen.com/english/advisories/2011/0212
bugs.launchpad.net/zodb/+bug/135108
bugzilla.redhat.com/show_bug.cgi?id=632200
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12210