CVE Vulnerabilities

CVE-2014-9365

Published: Dec 12, 2014 | Modified: Oct 25, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
4.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Ubuntu
MEDIUM

The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subjects (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected Software

Name Vendor Start Version End Version
Python Python 2.0 (including) 2.0 (including)
Python Python 2.0.1 (including) 2.0.1 (including)
Python Python 2.1 (including) 2.1 (including)
Python Python 2.1.1 (including) 2.1.1 (including)
Python Python 2.1.2 (including) 2.1.2 (including)
Python Python 2.1.3 (including) 2.1.3 (including)
Python Python 2.2 (including) 2.2 (including)
Python Python 2.2.1 (including) 2.2.1 (including)
Python Python 2.2.2 (including) 2.2.2 (including)
Python Python 2.2.3 (including) 2.2.3 (including)
Python Python 2.3.1 (including) 2.3.1 (including)
Python Python 2.3.2 (including) 2.3.2 (including)
Python Python 2.3.3 (including) 2.3.3 (including)
Python Python 2.3.4 (including) 2.3.4 (including)
Python Python 2.3.5 (including) 2.3.5 (including)
Python Python 2.3.7 (including) 2.3.7 (including)
Python Python 2.4.1 (including) 2.4.1 (including)
Python Python 2.4.2 (including) 2.4.2 (including)
Python Python 2.4.3 (including) 2.4.3 (including)
Python Python 2.4.4 (including) 2.4.4 (including)
Python Python 2.4.6 (including) 2.4.6 (including)
Python Python 2.5.1 (including) 2.5.1 (including)
Python Python 2.5.2 (including) 2.5.2 (including)
Python Python 2.5.3 (including) 2.5.3 (including)
Python Python 2.5.4 (including) 2.5.4 (including)
Python Python 2.5.6 (including) 2.5.6 (including)
Python Python 2.5.150 (including) 2.5.150 (including)
Python Python 2.6.1 (including) 2.6.1 (including)
Python Python 2.6.2 (including) 2.6.2 (including)
Python Python 2.6.3 (including) 2.6.3 (including)
Python Python 2.6.4 (including) 2.6.4 (including)
Python Python 2.6.5 (including) 2.6.5 (including)
Python Python 2.6.6 (including) 2.6.6 (including)
Python Python 2.6.7 (including) 2.6.7 (including)
Python Python 2.6.8 (including) 2.6.8 (including)
Python Python 2.6.2150 (including) 2.6.2150 (including)
Python Python 2.6.6150 (including) 2.6.6150 (including)
Python Python 2.7.1 (including) 2.7.1 (including)
Python Python 2.7.1-rc1 (including) 2.7.1-rc1 (including)
Python Python 2.7.2-rc1 (including) 2.7.2-rc1 (including)
Python Python 2.7.3 (including) 2.7.3 (including)
Python Python 2.7.4 (including) 2.7.4 (including)
Python Python 2.7.5 (including) 2.7.5 (including)
Python Python 2.7.6 (including) 2.7.6 (including)
Python Python 2.7.7 (including) 2.7.7 (including)
Python Python 2.7.8 (including) 2.7.8 (including)
Python Python 2.7.1150 (including) 2.7.1150 (including)
Python Python 2.7.2150 (including) 2.7.2150 (including)
Python Python 3.0 (including) 3.0 (including)
Python Python 3.0.1 (including) 3.0.1 (including)
Python Python 3.1 (including) 3.1 (including)
Python Python 3.1.1 (including) 3.1.1 (including)
Python Python 3.1.2 (including) 3.1.2 (including)
Python Python 3.1.3 (including) 3.1.3 (including)
Python Python 3.1.4 (including) 3.1.4 (including)
Python Python 3.1.5 (including) 3.1.5 (including)
Python Python 3.1.2150 (including) 3.1.2150 (including)
Python Python 3.2 (including) 3.2 (including)
Python Python 3.2-alpha (including) 3.2-alpha (including)
Python Python 3.2.0 (including) 3.2.0 (including)
Python Python 3.2.1 (including) 3.2.1 (including)
Python Python 3.2.2 (including) 3.2.2 (including)
Python Python 3.2.3 (including) 3.2.3 (including)
Python Python 3.2.4 (including) 3.2.4 (including)
Python Python 3.2.5 (including) 3.2.5 (including)
Python Python 3.2.6 (including) 3.2.6 (including)
Python Python 3.2.2150 (including) 3.2.2150 (including)
Python Python 3.3 (including) 3.3 (including)
Python Python 3.3-beta2 (including) 3.3-beta2 (including)
Python Python 3.3.0 (including) 3.3.0 (including)
Python Python 3.3.1 (including) 3.3.1 (including)
Python Python 3.3.1-rc1 (including) 3.3.1-rc1 (including)
Python Python 3.3.2 (including) 3.3.2 (including)
Python Python 3.3.3 (including) 3.3.3 (including)
Python Python 3.3.3-rc1 (including) 3.3.3-rc1 (including)
Python Python 3.3.3-rc2 (including) 3.3.3-rc2 (including)
Python Python 3.3.4 (including) 3.3.4 (including)
Python Python 3.3.4-rc1 (including) 3.3.4-rc1 (including)
Python Python 3.3.5 (including) 3.3.5 (including)
Python Python 3.3.5-rc1 (including) 3.3.5-rc1 (including)
Python Python 3.3.5-rc2 (including) 3.3.5-rc2 (including)
Python Python 3.3.6-rc1 (including) 3.3.6-rc1 (including)
Python Python 3.4-alpha1 (including) 3.4-alpha1 (including)
Python Python 3.4.0 (including) 3.4.0 (including)
Python Python 3.4.1 (including) 3.4.1 (including)
Python Python 3.4.2 (including) 3.4.2 (including)
Red Hat Enterprise Linux 7 RedHat python-0:2.7.5-58.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat python27-mod_wsgi-0:4.5.13-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat python27-python-0:2.7.13-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat python27-python-coverage-0:3.6-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat python27-python-pip-0:8.1.2-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat python27-python-setuptools-0:0.9.8-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat python27-python-virtualenv-0:13.1.0-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat python27-mod_wsgi-0:4.5.13-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat python27-python-0:2.7.13-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat python27-python-coverage-0:3.6-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat python27-python-pip-0:8.1.2-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat python27-python-setuptools-0:0.9.8-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat python27-python-virtualenv-0:13.1.0-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat python27-mod_wsgi-0:4.5.13-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat python27-python-0:2.7.13-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat python27-python-coverage-0:3.6-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat python27-python-pip-0:8.1.2-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat python27-python-setuptools-0:0.9.8-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat python27-python-virtualenv-0:13.1.0-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat python27-mod_wsgi-0:4.5.13-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat python27-python-0:2.7.13-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat python27-python-coverage-0:3.6-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat python27-python-pip-0:8.1.2-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat python27-python-setuptools-0:0.9.8-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS RedHat python27-python-virtualenv-0:13.1.0-2.el7 *
Python2.7 Ubuntu esm-infra-legacy/trusty *
Python2.7 Ubuntu precise *
Python2.7 Ubuntu precise/esm *
Python2.7 Ubuntu trusty *
Python2.7 Ubuntu trusty/esm *
Python2.7 Ubuntu upstream *
Python3.2 Ubuntu precise *
Python3.4 Ubuntu trusty *
Python3.4 Ubuntu upstream *

References