Skip to content
appaloosa scout logo main rounded
MEDIUM 5.9

CVE-2013-7440

The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS 0.4% percentile 58.1%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
python python Windows ≤2.7.8 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.0.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.2:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.3:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.4:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.5:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.2150:*:*:*:*:*:x64:*
python python Windows cpe:2.3:a:python:python:3.2:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2:alpha:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.2:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.3:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.4:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.5:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.6:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.2150:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3:beta2:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.1:rc1:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*
View on NVD ↗