Oval Definition:oval:org.mitre.oval:def:24190
Revision Date:2014-05-26Version:15
Title:ELSA-2013:1582: python security, bug fix, and enhancement update (Moderate)
Description:The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-4238
ELSA-2013:1582-02
Platform(s):Oracle Linux 6
Product(s):python
Definition Synopsis
  • Oracle Linux 6.x
  • AND rpm test
  • tkinter is earlier than 0:2.6.6-51.el6
  • OR python-tools is earlier than 0:2.6.6-51.el6
  • OR python-test is earlier than 0:2.6.6-51.el6
  • OR python is earlier than 0:2.6.6-51.el6
  • OR python-libs is earlier than 0:2.6.6-51.el6
  • OR python-devel is earlier than 0:2.6.6-51.el6
  • BACK