First published: Tue Oct 19 2010(Updated: )
Race condition in `ZEO/StorageServer.py` in Zope Object Database (ZODB) before 3.10.0a2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/zodb3 | <3.10.0a2 | 3.10.0a2 |
Zope ZODB | <=3.9.7 | |
Zope ZODB | =2.8.11 | |
Zope ZODB | =2.9.11 | |
Zope ZODB | =2.10.9 | |
Zope ZODB | =2.11.4 | |
Zope ZODB | =3.1 | |
Zope ZODB | =3.1.1 | |
Zope ZODB | =3.2 | |
Zope ZODB | =3.2.4 | |
Zope ZODB | =3.3 | |
Zope ZODB | =3.3.3 | |
Zope ZODB | =3.4 | |
Zope ZODB | =3.4.1 | |
Zope ZODB | =3.5 | |
Zope ZODB | =3.6 | |
Zope ZODB | =3.7 | |
Zope ZODB | =3.8 | |
Zope ZODB | =3.8.0 | |
Zope ZODB | =3.8.1 | |
Zope ZODB | =3.8.2 | |
Zope ZODB | =3.8.6 | |
Zope ZODB | =3.9.0 | |
Zope ZODB | =3.9.0b1 | |
Zope ZODB | =3.9.0b2 | |
Zope ZODB | =3.9.0b3 | |
Zope ZODB | =3.9.0b4 | |
Zope ZODB | =3.9.0b5 | |
Zope ZODB | =3.9.0c1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3495 has been classified as a vulnerability that can lead to a denial of service due to a race condition.
To fix CVE-2010-3495, upgrade to ZODB version 3.10.0a2 or later.
CVE-2010-3495 affects all versions of Zope Object Database (ZODB) prior to 3.10.0a2.
Yes, CVE-2010-3495 enables remote attackers to cause denial of service by manipulating TCP connections.
CVE-2010-3495 can result in daemon outages, impacting service availability.