4.3
CVSSv2

CVE-2010-3495

Published: 19/10/2010 Updated: 22/01/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Race condition in ZEO/StorageServer.py in Zope Object Database (ZODB) prior to 3.10.0 allows remote malicious users to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.

Vulnerable Product Search on Vulmon Subscribe to Product

zope zodb 2.10.9

zope zodb 2.11.4

zope zodb 3.8.0

zope zodb 3.5

zope zodb 3.6

zope zodb 3.4.1

zope zodb 3.4

zope zodb 2.9.11

zope zodb 3.9.0b5

zope zodb 3.9.0b3

zope zodb 3.7

zope zodb 3.1.1

zope zodb 3.1

zope zodb 3.8.6

zope zodb 3.9.0

zope zodb 3.8.2

zope zodb 3.8.1

zope zodb 3.8

zope zodb 3.3.3

zope zodb 3.3

zope zodb 2.8.11

zope zodb 3.9.0b4

zope zodb 3.9.0b1

zope zodb 3.9.0b2

zope zodb 3.2.4

zope zodb 3.2

zope zodb 3.9.0c1

zope zodb

Vendor Advisories

Debian Bug report logs - #599711 CVE-2010-3495 Package: zodb; Maintainer for zodb is Debian/Ubuntu Zope Team <pkg-zope-developers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 10 Oct 2010 11:24:08 UTC Severity: important Tags: patch, security Fixed in version zodb/1:394-11 ...