• CVE-2024-3219

发布时间: 2024年9月27日

修改时间: 2024年9月29日

概要

There is a MEDIUM severity vulnerability affecting CPython. The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing the two sockets back to the user, which leaves the server socket vulnerable to a connection race from a malicious local peer. Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Local
CVSS评分 N/A 4.0
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity None
User Interaction None
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3839 python3 security update 2024年10月26日
KylinSec-SA-2024-4872 python3 security update 2025年2月17日

影响产品

产品 状态
KY3.5.2 python3 Fixed
V6 python3 Fixed
KY3.5.3 python3 Fixed