CVE-2019-5010
🟡 Monitoruj
Wykorzystanie podatności w parserze certyfikatów X509 w Pythonie prowadzi do odmowy usługi.
CVSS
7.5
EPSS
20.7%
Exploit
poc
Vendor
redhat
Opis źródłowy (NVD)
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 20.7% |
| Opublikowano (NVD) | 2019-10-31 21:15:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 19:17:14 UTC |
Referencje
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html ([email protected]) [Mailing List, Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3520 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3725 ([email protected]) [Third Party Advisory]
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E ([email protected])
- https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html ([email protected]) [Mailing List, Third Party Advisory]
- https://security.gentoo.org/glsa/202003-26 ([email protected]) [Third Party Advisory]
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758 ([email protected]) [Exploit, Third Party Advisory]