Improper Input Validation Affecting python2.7 package, versions <2.7.3~rc1-1


0.0
medium

Snyk CVSS

    Attack Complexity Low
    User Interaction Required
NVD  medium
Red Hat  medium
Expand this section
SUSE
3.7 low

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN9-PYTHON27-306575
  • published 6 Sep 2011
  • disclosed 6 Sep 2011

How to fix?

Upgrade Debian:9 python2.7 to version 2.7.3~rc1-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python2.7 package and not the python2.7 package as distributed by Debian:9. See How to fix? for Debian:9 relevant fixed versions and status.

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.