Lucene search

K
redhatRedHatRHSA-2014:1690
HistoryOct 22, 2014 - 12:00 a.m.

(RHSA-2014:1690) Low: python-backports-ssl_match_hostname security update

2014-10-2200:00:00
access.redhat.com
29

0.053 Low

EPSS

Percentile

93.1%

The python-backports-ssl_match_hostname package provides RFC 6125 compliant
wildcard matching.

A denial of service flaw was found in the way Python’s SSL module
implementation performed matching of certain certificate names. A remote
attacker able to obtain a valid certificate that contained multiple
wildcard characters could use this flaw to issue a request to validate such
a certificate, resulting in excessive consumption of CPU. (CVE-2013-2099)

This issue was discovered by Florian Weimer of Red Hat Product Security.

All python-backports-ssl_match_hostname users are advised to upgrade to
this updated package, which contains a backported patch to correct this
issue.