Back

MEDIUM

python accept() implementation in async core is broken

Published Oct 19, 2010

Description

The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.

Affected products

Remediation

Red Hat statement

This issue affects the version of the python package as shipped with Red Hat Enterprise Linux 4, 5, and 6. Due to the nature of this flaw, it cannot be fixed in the python language, but must be addressed in each module which calls accept().

Metrics

Weaknesses (0)

No CWE recorded.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 19, 2010
Updated Aug 7, 2024
Reserved Sep 24, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Sep 9, 2010