CVE-2016-0772
CVE-2016-0772
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
Productos afectados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/43500no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1626.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1627.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1628.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1629.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1630.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1303647https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-5https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-2https://hg.python.org/cpython/raw-file/v2.7.12/Misc/NEWShttps://hg.python.org/cpython/rev/b3ce713fb9behttps://hg.python.org/cpython/rev/d590114c2394