Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1xNDhxLTc3cXYtY2Y5cM4AAUp3
httplib2 incorrectly checks SSL certificate
httplib2 prior to version 0.10.1, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Permalink: https://github.com/advisories/GHSA-q48q-77qv-cf9pJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNDhxLTc3cXYtY2Y5cM4AAUp3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: about 2 years ago
Updated: 17 days ago
Identifiers: GHSA-q48q-77qv-cf9p, CVE-2013-2037
References:
- https://nvd.nist.gov/vuln/detail/CVE-2013-2037
- https://bugs.launchpad.net/httplib2/+bug/1175272
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602
- http://code.google.com/p/httplib2/issues/detail?id=282
- http://seclists.org/oss-sec/2013/q2/257
- http://www.ubuntu.com/usn/USN-1948-1
- https://github.com/httplib2/httplib2/issues/5
- https://github.com/httplib2/httplib2/commit/40cbdcc8586f2292fa0e76a3e8c012f0cc9ed919
- https://web.archive.org/web/20200228052625/http://www.securityfocus.com/bid/52179
- https://github.com/advisories/GHSA-q48q-77qv-cf9p
Blast Radius: 0.0
Affected Packages
pypi:httplib2
Dependent packages: 266Dependent repositories: 48,310
Downloads: 41,633,749 last month
Affected Version Ranges: < 0.10.1
Fixed in: 0.10.1
All affected versions: 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.9.1, 0.9.2
All unaffected versions: 0.10.3, 0.11.0, 0.11.1, 0.11.3, 0.12.0, 0.12.1, 0.12.3, 0.13.0, 0.13.1, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.17.1, 0.17.2, 0.17.3, 0.17.4, 0.18.0, 0.18.1, 0.19.0, 0.19.1, 0.20.0, 0.20.1, 0.20.2, 0.20.4, 0.21.0, 0.22.0