CVE-2010-3492
Last modified
CVE-2010-3492 is a vulnerability of currently unknown severity. The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.. EPSS estimates a 3.63% chance of exploitation in the next 30 days.
Description
The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Python | Python | <= 2.7 |
| Python | Python | >= 3.0, < 3.1.2 |
References
- http://bugs.python.org/issue6706Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:215Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:216Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/09/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/11/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/22/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/24/3Mailing List, Third Party Advisory
- http://bugs.python.org/issue6706Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:215Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:216Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/09/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/11/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/22/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/24/3Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3492?
How severe is CVE-2010-3492?
How do I fix CVE-2010-3492?
Are you affected by CVE-2010-3492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
