Scientific Linux Security Update : python on SL6.x i386/x86_64

Medium Nessus Plugin ID 71199


The remote Scientific Linux host is missing one or more security updates.


A flaw was found in the way the Python SSL module handled X.509 certificate fields that contain a NULL byte. An attacker could potentially exploit this flaw to conduct man-in-the-middle attacks to spoof SSL servers. Note that to exploit this issue, an attacker would need to obtain a carefully crafted certificate signed by an authority that the client trusts. (CVE-2013-4238)


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 71199

File Name: sl_20131121_python_on_SL6_x.nasl

Version: $Revision: 1.3 $

Type: local

Agent: unix

Published: 2013/12/04

Modified: 2014/12/15

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2013/11/21

Reference Information

CVE: CVE-2013-4238