CVE-2016-0772
CVE-2016-0772
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
Produtos afetados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/43500não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1626.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1627.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1628.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1629.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1630.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1303647https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-5https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-2https://hg.python.org/cpython/raw-file/v2.7.12/Misc/NEWShttps://hg.python.org/cpython/rev/b3ce713fb9behttps://hg.python.org/cpython/rev/d590114c2394