CVE-2013-4238: Input Validation

Published Aug 13, 2013
·
Updated

A flaw was found in the way ssl.matchhostname() from the Python SSL module checked the hostname's identity when handling certificates that contain hostnames with NULL bytes. An attacker could potentially exploit this flaw to conduct man-in-the-middle attacks to spoof SSL servers. Note that to exploit this issue, an attacker would need to obtain a carefully-crafted certificate signed by an authority that the client trusts.

References:

http://bugs.python.org/issue18709 http://bugs.python.org/file31241/CVE-2013-4073py34.patch http://bugs.python.org/file31242/CVE-2013-4073py33.patch http://bugs.python.org/file31243/CVE-2013-4073py27.patch

Other sources

The ssl.matchhostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

MITRE

Affected Software

37 affected components
Canonical Ubuntu Linux=10.04
Python Python=2.6.1
Python Python=2.6.2
Python Python=2.6.3
Python Python=2.6.4
Python Python=2.6.5
Python Python=2.6.6
Python Python=2.6.7
Python Python=2.6.8
Python Python=2.6.2150
Python Python=2.6.6150
Python Python=2.7.1
Python Python=2.7.1-rc1
Python Python=2.7.2-rc1
Python Python=2.7.3
Python Python=2.7.1150
Python Python=2.7.1150
Python Python=2.7.2150
Python Python=3.0
Python Python=3.0.1
Python Python=3.1
Python Python=3.1.1
Python Python=3.1.2
Python Python=3.1.3
Python Python=3.1.4
Python Python=3.1.5
Python Python=3.1.2150
Python Python=3.2
Python Python=3.2-alpha
Python Python=3.2.3
Python Python=3.2.2150
Python Python=3.3
Python Python=3.3-beta2
Python Python=3.4-alpha1
openSUSE openSUSE=11.4
openSUSE openSUSE=12.2
openSUSE openSUSE=12.3

Event History

Aug 13, 2013
Data Sourced
05:39 AM
DescriptionSeverityAffected Software
Aug 18, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2013-4238?

CVE-2013-4238 has a moderate severity level due to the potential for man-in-the-middle attacks.

2

How do I fix CVE-2013-4238?

To fix CVE-2013-4238, upgrade to a version of Python where the vulnerability has been patched.

3

Which versions of Python are affected by CVE-2013-4238?

CVE-2013-4238 affects multiple versions of Python, including 2.6.1 through 3.4 and several Ubuntu versions.

4

What kind of attacks can CVE-2013-4238 be exploited for?

CVE-2013-4238 can be exploited to carry out man-in-the-middle attacks, allowing attackers to spoof SSL servers.

5

Is CVE-2013-4238 related to SSL certificate validation?

Yes, CVE-2013-4238 is specifically related to how ssl.match_hostname() validates SSL certificate hostnames.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203