pyopenssl_project/pyopenssl: The latest CVE Vulnerabilities and Exploits for Penetration Test

 

Page content

pyopenssl_project/pyopenssl Vulnerability Summary

  • Vendor name: pyopenssl_project
  • Product name: pyopenssl
  • Total vulnerabilities: 1 (as 2023-05-04)

pyopenssl_project/pyopenssl Vulnerability List

CVE-2018-1000808: Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to…

Published: 2018-10-08T15:29:00 Last Modified: 2021-08-04T17:14:00

Summary

Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploitable via Depends upon calling application, however it could be as simple as initiating a TLS connection. Anything that would cause the calling application to reload certificates from a PKCS #12 store.. This vulnerability appears to have been fixed in 17.5.0.

Common Weakness Enumeration (CWE): CWE-404: Improper Resource Shutdown or Release

CWE Description: Improper release or shutdown of resources can be resultant from improper error handling or insufficient resource tracking.

Scores

  • Impact Score: 2.9
  • Exploitability Score: 8.6
  • CVSS: 4.3
  • CVSS Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Impact

  • Availability: PARTIAL
  • Confidentiality: NONE
  • Integrity: NONE

Access

  • Authentication: NONE
  • Complexity: MEDIUM
  • Vector: NETWORK

Currently, there is no code for exploiting the CVE-2018-1000808 vulnerability.

References

See also: All popular products CVE Vulnerabilities of pyopenssl_project