An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1663-1 | python3.4 security update |
Debian DLA |
DLA-1834-1 | python2.7 security update |
Debian DLA |
DLA-2280-1 | python3.5 security update |
Debian DLA |
DLA-2337-1 | python2.7 security update |
EUVD |
EUVD-2019-14617 | An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability. |
Ubuntu USN |
USN-4127-1 | Python vulnerabilities |
Ubuntu USN |
USN-4127-2 | Python vulnerabilities |
Ubuntu USN |
USN-6891-1 | Python vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-04T19:40:49.196Z
Reserved: 2019-01-04T00:00:00
Link: CVE-2019-5010
No data.
Status : Modified
Published: 2019-10-31T21:15:13.293
Modified: 2024-11-21T04:44:10.850
Link: CVE-2019-5010
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN