CVE-2010-3492
Last modified
CVE-2010-3492 is a vulnerability of currently unknown severity. The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.. EPSS estimates a 3.63% chance of exploitation in the next 30 days.
Description
The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Python | Python | <= 2.7 |
| Python | Python | >= 3.0, < 3.1.2 |
References
- http://bugs.python.org/issue6706Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:215Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:216Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/09/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/11/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/22/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/24/3Mailing List, Third Party Advisory
- http://bugs.python.org/issue6706Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:215Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:216Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/09/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/11/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/22/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2010/09/24/3Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3492?
How severe is CVE-2010-3492?
How do I fix CVE-2010-3492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3486Directory traversal vulnerability in FileStorageUpload.ashx …
- CVE-2010-3487Directory traversal vulnerability in YelloSoft Pinky 1.0 for…
- CVE-2010-3488Directory traversal vulnerability in QuickShare 1.0 allows r…
- CVE-2010-3489Cross-site scripting (XSS) vulnerability in netautor/napro4/…
- CVE-2010-3490Directory traversal vulnerability in page.recordings.php in …
- CVE-2010-3491The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administra…
- CVE-2010-3493Multiple race conditions in smtpd.py in the smtpd module in …
- CVE-2010-3494Race condition in the FTPHandler class in ftpserver.py in py…
- CVE-2010-3495Race condition in ZEO/StorageServer.py in Zope Object Databa…
- CVE-2010-3496McAfee VirusScan Enterprise 8.5i and 8.7i does not properly …
- CVE-2010-3497Symantec Norton AntiVirus 2011 does not properly interact wi…
- CVE-2010-3498AVG Anti-Virus does not properly interact with the processin…
Are you affected by CVE-2010-3492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
