Skip to content
appaloosa scout logo main rounded
MEDIUM 6.5

CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS 7.6% percentile 92.0%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
python python Windows cpe:2.3:a:python:python:3.5.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.5.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.0.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.2:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.3:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.4:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.1.5:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.2:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.3:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.4:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.5:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.2.6:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.4:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.5:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.3.6:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.4.0:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.4.1:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.4.2:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.4.3:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.4.4:*:*:*:*:*:*:*
python python Windows ≤2.7.11 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
View on NVD ↗