Ubuntu Security Notice (C) 2013 Canonical, Inc. / NASL script (C) 2013-2014 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
Florian Weimer discovered that Python incorrectly handled matching
multiple wildcards in ssl certificate hostnames. An attacker could
exploit this to cause Python to consume resources, resulting in a
denial of service. (CVE-2013-2099)
Ryan Sleevi discovered that Python did not properly handle
certificates with NULL characters in the Subject Alternative Name
field. An attacker could exploit this to perform a man in the middle
attack to view sensitive information or alter encrypted
Update the affected python3.2 and / or python3.2-minimal packages.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : true