CVE-2023-29483

HIGHCVSS 7/10EPSS 1.86%

Last modified

CVE-2023-29483 is a high-severity vulnerability rated 7/10 on the CVSS scale. eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. EPSS estimates a 1.86% chance of exploitation in the next 30 days.

Description

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

Metrics

CVSS 3.1
7/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

EPSS Probability
1.86%

76.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
EventletEventlet< 0.35.2
DnspythonDnspython< 2.6.0
FedoraprojectFedora38
FedoraprojectFedora39
FedoraprojectFedora40
NetappBootstrap OsAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-29483?
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
How severe is CVE-2023-29483?
CVE-2023-29483 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 1.86% probability of exploitation in the next 30 days.
How do I fix CVE-2023-29483?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-29483?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST