CVE-2024-5642
27.06.2024, 21:15
CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely used and specifying an empty list likely being uncommon in-practice (typically a protocol name would be configured).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.

Debian Releases
Debian Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
pypy3 |
| ||||||||||
python2.7 |
| ||||||||||
python3.11 |
| ||||||||||
python3.12 |
| ||||||||||
python3.13 |
| ||||||||||
python3.9 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python2.7 |
| ||||||||||||||||||
python3.10 |
| ||||||||||||||||||
python3.11 |
| ||||||||||||||||||
python3.12 |
| ||||||||||||||||||
python3.4 |
| ||||||||||||||||||
python3.5 |
| ||||||||||||||||||
python3.6 |
| ||||||||||||||||||
python3.7 |
| ||||||||||||||||||
python3.8 |
| ||||||||||||||||||
python3.9 |
|
References