[issue35746] TALOS-2018-0758 Denial of Service

2019-01-15 Thread Cisco Talos


New submission from Cisco Talos :

An exploitable denial-of-service vulnerability exists in the X509 certificate 
parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 
certificate can cause a NULL pointer dereference, resulting in a denial of 
service. An attacker can initiate or accept TLS connections using crafted 
certificates to trigger this vulnerability.

--
files: TALOS-2019-0758.txt
messages: 333709
nosy: Talos
priority: normal
severity: normal
status: open
title: TALOS-2018-0758 Denial of Service
type: security
versions: Python 2.7, Python 3.4, Python 3.5, Python 3.6, Python 3.7, Python 3.8
Added file: https://bugs.python.org/file48052/TALOS-2019-0758.txt

___
Python tracker 
<https://bugs.python.org/issue35746>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue35746] TALOS-2018-0758 Denial of Service

2019-01-15 Thread Cisco Talos


Change by Cisco Talos :


--
versions:  -Python 3.4, Python 3.5, Python 3.6, Python 3.7, Python 3.8
Added file: https://bugs.python.org/file48053/TALOS-2019-0758 - POC.pem

___
Python tracker 
<https://bugs.python.org/issue35746>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue35746] TALOS-2018-0758 Denial of Service

2019-01-15 Thread Cisco Talos

Cisco Talos  added the comment:

Thanks for acknowledging.  We look forward to any updates/developments on the 
issue reported.

For further information about the Cisco Vendor Vulnerability Reporting and 
Disclosure Policy please refer to this document which also links to our public 
PGP key. 
https://tools.cisco.com/security/center/resources/vendor_vulnerability_policy.html

Kind Regards,

Regina Wilson
Analyst.Business Operations
regiw...@cisco.com<mailto:regiw...@cisco.com>

[cid:CFA14CB5-B7B2-4FF7-8313-22D495F607D5@vrt.sourcefire.com]

On Jan 15, 2019, at 11:30 AM, Christian Heimes 
mailto:rep...@bugs.python.org>> wrote:

Christian Heimes mailto:li...@cheimes.de>> added the comment:

Thanks for the report!

--
assignee:  -> christian.heimes
components: +SSL
nosy: +christian.heimes
stage:  -> needs patch
versions: +Python 3.4, Python 3.5, Python 3.6, Python 3.7, Python 3.8

___
Python tracker mailto:rep...@bugs.python.org>>
<https://bugs.python.org/issue35746>
___

--
Added file: https://bugs.python.org/file48054/image001.png

___
Python tracker 
<https://bugs.python.org/issue35746>
__
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue35746] TALOS-2018-0758 Denial of Service

2019-01-15 Thread Cisco Talos


Change by Cisco Talos :


Removed file: https://bugs.python.org/file48052/TALOS-2019-0758.txt

___
Python tracker 
<https://bugs.python.org/issue35746>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue35746] TALOS-2018-0758 Denial of Service

2019-01-15 Thread Cisco Talos


Change by Cisco Talos :


Removed file: https://bugs.python.org/file48053/TALOS-2019-0758 - POC.pem

___
Python tracker 
<https://bugs.python.org/issue35746>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue35746] TALOS-2018-0758 Denial of Service

2019-01-15 Thread Cisco Talos

Cisco Talos  added the comment:

The files are removed and will be reissued to PSIRT.

Regina Wilson
Analyst.Business Operations
regiw...@cisco.com<mailto:regiw...@cisco.com>

[cid:CFA14CB5-B7B2-4FF7-8313-22D495F607D5@vrt.sourcefire.com]

On Jan 15, 2019, at 12:11 PM, Cisco Talos 
mailto:rep...@bugs.python.org>> wrote:

Change by Cisco Talos mailto:vuln...@cisco.com>>:

Removed file: https://bugs.python.org/file48052/TALOS-2019-0758.txt

___
Python tracker mailto:rep...@bugs.python.org>>
<https://bugs.python.org/issue35746>
___

--
Added file: https://bugs.python.org/file48055/image001.png

___
Python tracker 
<https://bugs.python.org/issue35746>
__
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com