Vulnerability Name:

CVE-2013-2037 (CCN-73490)

Assigned:2011-10-26
Published:2011-10-26
Updated:2018-12-06
Summary:httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Obtain Information
References:Source: CONFIRM
Type: Issue Tracking, Mailing List, Third Party Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602

Source: CCN
Type: python-httplib2 Web page
python-httplib2

Source: CONFIRM
Type: Exploit, Third Party Advisory
http://code.google.com/p/httplib2/issues/detail?id=282

Source: MITRE
Type: CNA
CVE-2013-2037

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20130501 Re: CVE Request: httplib2 ssl cert incorrect error handling

Source: CCN
Type: IBM Security Bulletin T1022877
Vulnerability in Python-httplib2 affects PowerKVM (CVE-2013-2037)

Source: CCN
Type: OSVDB ID: 79666
Python httplib2 HTTPS Connection Server Validation Weakness MitM Remote Information Disclosure

Source: BID
Type: Third Party Advisory, VDB Entry
52179

Source: CCN
Type: BID-52179
python-httplib2 CVE-2013-2037 SSL Certificate Validation Security Bypass Vulnerability

Source: UBUNTU
Type: Third Party Advisory
USN-1948-1

Source: CONFIRM
Type: Exploit, Patch
https://bugs.launchpad.net/httplib2/+bug/1175272

Source: CCN
Type: Ubuntu Bug #882030
python-httplib2 < 0.7.0 doesn't validate server certificates

Source: XF
Type: UNKNOWN
python-httplib2-info-disclosure(73490)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:httplib2_project:httplib2:*:*:*:*:*:*:*:* (Version <= 0.7.2)
  • OR cpe:/a:httplib2_project:httplib2:0.8:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:26219
    P
    Security update for apache2 (Important) (in QA)
    2022-01-10
    oval:org.opensuse.security:def:20132037
    V
    CVE-2013-2037
    2021-08-15
    oval:org.opensuse.security:def:26208
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:26207
    P
    Security update for openssl-1_1 (Moderate)
    2021-03-09
    oval:org.opensuse.security:def:26837
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26703
    P
    fvwm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27832
    P
    Security update for lxc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26925
    P
    kde4-kgreeter-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26844
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26411
    P
    Security update for go (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26418
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26983
    P
    libzip1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27048
    P
    unrar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26549
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26430
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27656
    P
    Security update for python-httplib2
    2020-12-01
    oval:org.opensuse.security:def:27136
    P
    gnome-screensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26784
    P
    mono-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26622
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27194
    P
    liblzo2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26886
    P
    ecryptfs-utils-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26760
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26283
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27867
    P
    Security update for python-httplib2
    2020-12-01
    oval:org.opensuse.security:def:26939
    P
    libadns1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26995
    P
    nagios-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26492
    P
    Security update for icingaweb2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26419
    P
    Security update for mbedtls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27621
    P
    Security update for gtk2
    2020-12-01
    oval:org.opensuse.security:def:27097
    P
    compat-libldap-2_3-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26633
    P
    python on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26494
    P
    Security update for pdns-recursor (Important)
    2020-12-01
    oval:org.opensuse.security:def:27150
    P
    jakarta-commons-fileupload on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:18479
    P
    USN-1948-1 -- python-httplib2 vulnerability
    2014-06-30
    oval:com.ubuntu.precise:def:20132037000
    V
    CVE-2013-2037 on Ubuntu 12.04 LTS (precise) - medium.
    2014-01-18
    BACK
    canonical ubuntu linux 10.04
    canonical ubuntu linux 12.04
    canonical ubuntu linux 12.10
    canonical ubuntu linux 13.04
    httplib2_project httplib2 *
    httplib2_project httplib2 0.8