MGASA-2013-0277
Dashboard / Vulnerabilities / MGASA-2013-0277
Summary: Updated python-OpenSSL package fixes security vulnerability
Details: The string formatting of subjectAltName X509Extension instances in pyOpenSSL before 0.13.1 incorrectly truncated fields of the name when encountering a null byte, possibly allowing man-in-the-middle attacks through certificate spoofing (CVE-2013-4314).
References: https://advisories.mageia.org/MGASA-2013-0277.html, https://bugs.mageia.org/show_bug.cgi?id=11206, https://mail.python.org/pipermail/pyopenssl-users/2013-September/000478.html, https://bugzilla.redhat.com/show_bug.cgi?id=1005325
Affected packages
Package
Name: python-OpenSSL
Purl: pkg:rpm/mageia/python-OpenSSL?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.12-1.1.mga2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
