UBUNTU-CVE-2013-2099
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-2099
UBUNTU-CVE-2013-2099
Summary:
Details: Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
References: https://ubuntu.com/security/CVE-2013-2099, http://www.openwall.com/lists/oss-security/2013/05/16/6, http://bugs.python.org/issue17980, https://ubuntu.com/security/notices/USN-1983-1, https://ubuntu.com/security/notices/USN-1985-1, https://ubuntu.com/security/notices/USN-1984-1, https://www.cve.org/CVERecord?id=CVE-2013-2099
Affected packages
Package
Name: w3af
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
