5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
0.115 Low
EPSS
Percentile
95.3%
Multiple race conditions in smtpd.py in the smtpd module in Python 2.6,
2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service
(daemon outage) by establishing and then immediately closing a TCP
connection, leading to the accept function having an unexpected return
value of None, an unexpected value of None for the address, or an
ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function
having an ENOTCONN error, a related issue to CVE-2010-3492.
Author | Note |
---|---|
jdstrand | python3.1 on Ubuntu 10.10 has additional patches on top of 3.1.2, including a fix for this issue |
launchpad.net/bugs/cve/CVE-2010-3493
nvd.nist.gov/vuln/detail/CVE-2010-3493
security-tracker.debian.org/tracker/CVE-2010-3493
ubuntu.com/security/notices/USN-1314-1
ubuntu.com/security/notices/USN-1596-1
ubuntu.com/security/notices/USN-1613-1
ubuntu.com/security/notices/USN-1613-2
www.cve.org/CVERecord?id=CVE-2010-3493