CVE-2013-2099: Medium severity ibm cognos analytics vulnerability
A denial of service flaw was found in the way SSL module implementation of Python3, version 3 of the Python programming language (aka Python 3000), performed matching of the certificate's name in the case it contained many '' wildcard characters. A remote attacker, able to obtain valid certificate with its name containing a lot of '' wildcard characters could use this flaw to cause denial of service (excessive CPU consumption) by issuing request to validate such a certificate for / to an application using the Python's ssl.matchhostname() functionality.
Upstream bug report: [1] http://bugs.python.org/issue17980
CVE request: [2] http://www.openwall.com/lists/oss-security/2013/05/15/6 (is for python-backports-sslmatchhostname, but that code comes from Python 3.2 ssl module implementation) [3] http://www.openwall.com/lists/oss-security/2013/05/15/7
Acknowledgements:
Name: Florian Weimer (Red Hat Product Security)
Other sources
Algorithmic complexity vulnerability in the ssl.matchhostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-sslmatchhostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
— MITRE
Python is vulnerable to a denial of service, caused by an error in the ssl.matchhostname() function when matching certificates with multiple wildcard characters. By sending a specially-crafted SSL certificate containing wildcard characters, a remote attacker could exploit this vulnerability to cause the application to consume an overly large amount of CPU resources.
Note: This vulnerability also affects Red Hat Storage.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2099?
CVE-2013-2099 is classified as a denial-of-service vulnerability.
How do I fix CVE-2013-2099?
To fix CVE-2013-2099, you should apply the relevant patches provided by your software vendor.
Which software is affected by CVE-2013-2099?
CVE-2013-2099 affects specific versions of Python 3 and IBM Cognos Analytics.
What versions of Python are impacted by CVE-2013-2099?
CVE-2013-2099 impacts Python versions 3.2.0 through 3.3.2.
Is AWS affected by CVE-2013-2099?
CVE-2013-2099 does not specifically list AWS services as affected.