Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cpython 安全漏洞
Vulnerability Description
Python是Python软件基金会的一套开源的、面向对象的程序设计语言,该语言具有可扩展、支持模块和包、支持多种平台等特点。CPython(又名Python)是一款用C语言实现的Python解释器。 Cpython 2.7.9之前版本和3.3.3之前3.x版本的‘ssl.match_hostname’函数中存在安全漏洞,该漏洞源于程序没有正确处理域名中的通配符。攻击者可借助特制的证书利用该漏洞实施中间人攻击,欺骗服务器。
CVSS Information
N/A
Vulnerability Type
N/A