CVE-2013-2037
HIGH7.5EPSS 0.49%httplib2 incorrectly checks SSL certificate
發布日:2022/5/14修改日:2026/4/28
描述
httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
受影響套件(3)
- Debian/python-httplib2from 0, < 0.8-2
- PyPI/httplib2from 0, < 0.10.1
- PyPI/httplib2from 0, < 0.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
參考連結(13)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2013-2037
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2013-2037
- PATCHhttps://github.com/httplib2/httplib2
- WEBhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602
- WEBhttp://code.google.com/p/httplib2/issues/detail?id=282
- WEBhttps://bugs.launchpad.net/httplib2/+bug/1175272
- WEBhttp://seclists.org/oss-sec/2013/q2/257
- WEBhttps://github.com/httplib2/httplib2/commit/40cbdcc8586f2292fa0e76a3e8c012f0cc9ed919
- WEBhttps://github.com/httplib2/httplib2/issues/5
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2014-81.yaml
- WEBhttps://web.archive.org/web/20200228052625/http://www.securityfocus.com/bid/52179
- WEBhttp://www.securityfocus.com/bid/52179
- WEBhttp://www.ubuntu.com/usn/USN-1948-1