Search CVE reports
11 – 20 of 76 results
CVE-2024-3219
Medium priorityThe “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Not affected | Not affected | Not affected | Not affected |
python3.10 | Not in release | Not affected | Not in release | — | — |
python3.11 | Not in release | Not affected | Not in release | — | — |
python3.12 | Not affected | Not in release | Not in release | — | — |
python3.4 | Not in release | Not in release | Not in release | — | — |
python3.5 | Not in release | Not in release | Not in release | — | Not affected |
python3.6 | Not in release | Not in release | Not in release | Not affected | — |
python3.7 | Not in release | Not in release | Not in release | Not affected | — |
python3.8 | Not in release | Not in release | Not affected | Not affected | — |
python3.9 | Not in release | Not in release | Not affected | — | — |
CVE-2024-5642
Low priorityCPython 3.9 and earlier doesn’t disallow configuring an empty list (”[]”) for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
python3.10 | Not in release | Not affected | Not in release | — | — |
python3.11 | Not in release | Not affected | Not in release | — | — |
python3.12 | Not affected | Not in release | Not in release | — | — |
python3.4 | Not in release | Not in release | Not in release | — | — |
python3.5 | Not in release | Not in release | Not in release | — | Vulnerable |
python3.6 | Not in release | Not in release | Not in release | Not affected | — |
python3.7 | Not in release | Not in release | Not in release | Not affected | — |
python3.8 | Not in release | Not in release | Not affected | Not affected | — |
python3.9 | Not in release | Not in release | Needs evaluation | — | — |
CVE-2024-0397
Medium prioritySome fixes available 2 of 16
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
python3.10 | Not in release | Fixed | Not in release | — | — |
python3.11 | Not in release | Needs evaluation | Not in release | — | — |
python3.12 | Not affected | Not in release | Not in release | — | — |
python3.4 | Not in release | Not in release | Not in release | — | — |
python3.5 | Not in release | Not in release | Not in release | — | Not affected |
python3.6 | Not in release | Not in release | Not in release | Needs evaluation | — |
python3.7 | Not in release | Not in release | Not in release | Needs evaluation | — |
python3.8 | Not in release | Not in release | Fixed | Needs evaluation | — |
python3.9 | Not in release | Not in release | Needs evaluation | — | — |
CVE-2024-4032
Low prioritySome fixes available 4 of 13
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Not affected | Not affected | Not affected | Not affected |
python3.10 | Not in release | Fixed | Not in release | — | — |
python3.11 | Not in release | Needs evaluation | Not in release | — | — |
python3.12 | Fixed | Not in release | Not in release | — | — |
python3.4 | Not in release | Not in release | Not in release | — | — |
python3.5 | Not in release | Not in release | Not in release | — | Fixed |
python3.6 | Not in release | Not in release | Not in release | Needs evaluation | — |
python3.7 | Not in release | Not in release | Not in release | Needs evaluation | — |
python3.8 | Not in release | Not in release | Fixed | Needs evaluation | — |
python3.9 | Not in release | Not in release | Needs evaluation | — | — |
CVE-2024-4030
Medium priorityOn Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Not affected | Not affected | Not affected | Not affected |
python3.10 | Not in release | Not affected | Not in release | — | — |
python3.11 | Not in release | Not affected | Not in release | — | — |
python3.12 | Not affected | Not in release | Not in release | — | — |
python3.4 | Not in release | Not in release | Not in release | — | — |
python3.5 | Not in release | Not in release | Not in release | — | Not affected |
python3.6 | Not in release | Not in release | Not in release | Not affected | — |
python3.7 | Not in release | Not in release | Not in release | Not affected | — |
python3.8 | Not in release | Not in release | Not affected | Not affected | — |
python3.9 | Not in release | Not in release | Not affected | — | — |
CVE-2024-0450
Medium prioritySome fixes available 13 of 17
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Fixed | Fixed | Needs evaluation | Needs evaluation |
python3.10 | Not in release | Fixed | Not in release | — | — |
python3.11 | Not in release | Fixed | Not in release | — | — |
python3.12 | Not affected | Not in release | Not in release | — | — |
python3.4 | Not in release | Not in release | Not in release | — | — |
python3.5 | Not in release | Not in release | Not in release | — | Fixed |
python3.6 | Not in release | Not in release | Not in release | Fixed | — |
python3.7 | Not in release | Not in release | Not in release | Fixed | — |
python3.8 | Not in release | Not in release | Fixed | Fixed | — |
python3.9 | Not in release | Not in release | Fixed | — | — |
CVE-2023-6597
Medium prioritySome fixes available 9 of 10
An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Not affected | Not affected | Not affected | Not affected |
python3.10 | Not in release | Fixed | Not in release | — | — |
python3.11 | Not in release | Fixed | Not in release | — | — |
python3.12 | Not affected | Not in release | Not in release | — | — |
python3.4 | Not in release | Not in release | Not in release | — | — |
python3.5 | Not in release | Not in release | Not in release | — | Fixed |
python3.6 | Not in release | Not in release | Not in release | Not affected | — |
python3.7 | Not in release | Not in release | Not in release | Fixed | — |
python3.8 | Not in release | Not in release | Fixed | Fixed | — |
python3.9 | Not in release | Not in release | Fixed | — | — |
CVE-2023-6507
Medium priorityAn issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value...
6 affected packages
python2.7, python3.10, python3.11, python3.12, python3.7, python3.9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Not affected | Not affected | Not affected | Not affected |
python3.10 | Not in release | Not affected | Not in release | Ignored | Ignored |
python3.11 | Not in release | Not affected | Not in release | Ignored | Ignored |
python3.12 | Not affected | Not in release | Not in release | Ignored | Ignored |
python3.7 | Not in release | Not in release | Not in release | Not affected | Ignored |
python3.9 | Not in release | Not in release | Not affected | Ignored | Ignored |
CVE-2023-40217
Medium prioritySome fixes available 15 of 16
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side...
10 affected packages
python2.7, python3.10, python3.11, python3.12, python3.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python2.7 | Not in release | Fixed | Fixed | Fixed | Fixed |
python3.10 | Not in release | Fixed | Not in release | Ignored | Ignored |
python3.11 | Not in release | Fixed | Not in release | Ignored | Ignored |
python3.12 | Not affected | Not in release | Not in release | Ignored | Ignored |
python3.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
python3.5 | Not in release | Not in release | Not in release | Not in release | Fixed |
python3.6 | Not in release | Not in release | Not in release | Fixed | Not in release |
python3.7 | Not in release | Not in release | Not in release | Fixed | Ignored |
python3.8 | Not in release | Not in release | Fixed | Fixed | Not in release |
python3.9 | Not in release | Not in release | Fixed | Ignored | Ignored |
CVE-2023-41105
Medium priorityAn issue was discovered in Python 3.11 through 3.11.4. If a path containing ‘\0’ bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first ‘\0’ byte. There are plausible cases in which...
11 affected packages
python, python2.7, python3.10, python3.11, python3.12...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python | Not in release | Not in release | Not in release | Ignored | Ignored |
python2.7 | Not in release | Not affected | Not affected | Not affected | Not affected |
python3.10 | Not in release | Not affected | Not in release | Not in release | Not in release |
python3.11 | Not in release | Fixed | Not in release | Not in release | Not in release |
python3.12 | Not affected | Not in release | Not in release | Not in release | Not in release |
python3.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
python3.5 | Not in release | Not in release | Not in release | Not in release | Not affected |
python3.6 | Not in release | Not in release | Not in release | Not affected | Not in release |
python3.7 | Not in release | Not in release | Not in release | Not affected | Not in release |
python3.8 | Not in release | Not in release | Not affected | Not affected | Not in release |
python3.9 | Not in release | Not in release | Not affected | Not in release | Not in release |