Oval Definition:oval:com.ubuntu.precise:def:20149365000
Revision Date:2014-12-12Version:1
Title:CVE-2014-9365 on Ubuntu 12.04 LTS (precise) - medium.
Description:The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-9365
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • The 'python2.7' package in precise is affected and needs fixing.
  • OR The 'python3.2' package in precise is affected and needs fixing.
  • BACK