CVE-2010-3493
Last modified
CVE-2010-3493 is a vulnerability of currently unknown severity. Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492.. EPSS estimates a 2.77% chance of exploitation in the next 30 days.
Description
Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Python | Python | 3.1 | — |
| Python | Python | 3.2 | Alpha |
References
- http://bugs.python.org/issue6706Patch, Vendor Advisory
- http://bugs.python.org/issue9129Patch, Vendor Advisory
- http://bugs.python.org/issue6706Patch, Vendor Advisory
- http://bugs.python.org/issue9129Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3493?
How severe is CVE-2010-3493?
How do I fix CVE-2010-3493?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3487Directory traversal vulnerability in YelloSoft Pinky 1.0 for…
- CVE-2010-3488Directory traversal vulnerability in QuickShare 1.0 allows r…
- CVE-2010-3489Cross-site scripting (XSS) vulnerability in netautor/napro4/…
- CVE-2010-3490Directory traversal vulnerability in page.recordings.php in …
- CVE-2010-3491The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administra…
- CVE-2010-3492The asyncore module in Python before 3.2 does not properly h…
- CVE-2010-3494Race condition in the FTPHandler class in ftpserver.py in py…
- CVE-2010-3495Race condition in ZEO/StorageServer.py in Zope Object Databa…
- CVE-2010-3496McAfee VirusScan Enterprise 8.5i and 8.7i does not properly …
- CVE-2010-3497Symantec Norton AntiVirus 2011 does not properly interact wi…
- CVE-2010-3498AVG Anti-Virus does not properly interact with the processin…
- CVE-2010-3499F-Secure Anti-Virus does not properly interact with the proc…
Are you affected by CVE-2010-3493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
