CVE-2014-9365

The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
pythonpython
2.0
pythonpython
2.0.1
pythonpython
2.1
pythonpython
2.1.1
pythonpython
2.1.2
pythonpython
2.1.3
pythonpython
2.2
pythonpython
2.2.1
pythonpython
2.2.2
pythonpython
2.2.3
pythonpython
2.3.1
pythonpython
2.3.2
pythonpython
2.3.3
pythonpython
2.3.4
pythonpython
2.3.5
pythonpython
2.3.7
pythonpython
2.4.1
pythonpython
2.4.2
pythonpython
2.4.3
pythonpython
2.4.4
pythonpython
2.4.6
pythonpython
2.5.1
pythonpython
2.5.2
pythonpython
2.5.3
pythonpython
2.5.4
pythonpython
2.5.6
pythonpython
2.5.150
pythonpython
2.6.1
pythonpython
2.6.2
pythonpython
2.6.3
pythonpython
2.6.4
pythonpython
2.6.5
pythonpython
2.6.6
pythonpython
2.6.7
pythonpython
2.6.8
pythonpython
2.6.2150
pythonpython
2.6.6150
pythonpython
2.7.1
pythonpython
2.7.1:rc1
pythonpython
2.7.2:rc1
pythonpython
2.7.3
pythonpython
2.7.4
pythonpython
2.7.5
pythonpython
2.7.6
pythonpython
2.7.7
pythonpython
2.7.8
pythonpython
2.7.1150
pythonpython
2.7.1150
pythonpython
2.7.2150
pythonpython
3.0
pythonpython
3.0.1
pythonpython
3.1
pythonpython
3.1.1
pythonpython
3.1.2
pythonpython
3.1.3
pythonpython
3.1.4
pythonpython
3.1.5
pythonpython
3.1.2150
pythonpython
3.2
pythonpython
3.2:alpha
pythonpython
3.2.0
pythonpython
3.2.1
pythonpython
3.2.2
pythonpython
3.2.3
pythonpython
3.2.4
pythonpython
3.2.5
pythonpython
3.2.6
pythonpython
3.2.2150
pythonpython
3.3
pythonpython
3.3:beta2
pythonpython
3.3.0
pythonpython
3.3.1
pythonpython
3.3.1:rc1
pythonpython
3.3.2
pythonpython
3.3.3
pythonpython
3.3.3:rc1
pythonpython
3.3.3:rc2
pythonpython
3.3.4
pythonpython
3.3.4:rc1
pythonpython
3.3.5
pythonpython
3.3.5:rc1
pythonpython
3.3.5:rc2
pythonpython
3.3.6:rc1
pythonpython
3.4:alpha1
pythonpython
3.4.0
pythonpython
3.4.1
pythonpython
3.4.2
applemac_os_x
𝑥
≤ 10.10.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python2.7
bullseye
2.7.18-8+deb11u1
fixed
squeeze
no-dsa
wheezy
no-dsa
jessie
ignored
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
trusty
ignored
precise
ignored
python3.2
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
trusty
dne
precise
ignored
python3.4
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
not-affected
trusty
Fixed 3.4.3-1ubuntu1~14.04.2
released
precise
dne