UBUNTU-CVE-2019-5010
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-5010
UBUNTU-CVE-2019-5010
Summary:
Details: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2019-5010, https://github.com/python/cpython/pull/11569, https://python-security.readthedocs.io/vuln/ssl-crl-dps-dos.html, https://blog.talosintelligence.com/2019/01/vulnerability-spotlight-pythonorg.html, https://ubuntu.com/security/notices/USN-4127-1, https://ubuntu.com/security/notices/USN-4127-2, https://www.cve.org/CVERecord?id=CVE-2019-5010, https://ubuntu.com/security/notices/USN-6891-1
Affected packages
Package
Name: python3.4
Purl: pkg:deb/ubuntu/[email protected]~14.04.7+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
