4.3

CVE-2013-2191

python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 17
Fedoraproject ≫ Fedora Version 18
Opensuse ≫ Opensuse Version 11.4
Opensuse ≫ Opensuse Version 12.2
Opensuse ≫ Opensuse Version 12.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.9% 0.561
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-updates/2013-07/msg00025.html
http://lists.opensuse.org/opensuse-updates/2013-07/msg00026.html
http://www.openwall.com/lists/oss-security/2013/06/19/6
https://bugzilla.redhat.com/show_bug.cgi?id=951594
https://git.fedorahosted.org/cgit/python-bugzilla.git/commit/?id=a782282ee479ba4cc1b8b1d89700ac630ba83eef
Patch
https://lists.fedorahosted.org/pipermail/python-bugzilla/2013-June/000104.html