Impact: Moderate Public Date: 2019-01-15 CWE: CWE-476 Bugzilla: 1666519: CVE-2019-5010 python: NULL pointer dereference using a specially crafted X509 certificate A null pointer dereference vulnerability was found in the certificate parsing code in Python. This causes a denial of service to applications when parsing specially crafted certificates. This vulnerability is unlikely to be triggered if application enables SSL/TLS certificate validation and accepts certificates only from trusted root certificate authorities.
Find out more about CVE-2019-5010 from the MITRE CVE dictionary dictionary and NIST NVD.
This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5 and 6.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 7.5 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity Impact | None |
Availability Impact | High |
Platform | Package | State |
---|---|---|
Red Hat Software Collections for Red Hat Enterprise Linux | rh-python35-python | Affected |
Red Hat Software Collections for Red Hat Enterprise Linux | rh-python36-python | Affected |
Red Hat Enterprise Linux 7 | python | Affected |
Red Hat Enterprise Linux 6 | python | Not affected |
Red Hat Enterprise Linux 5 | python | Not affected |