← All CVEs

CVE-2016-0772

medium · 6.5

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

6.5
CVSS
14.5%
EPSS (exploit prob.)
96th
EPSS percentile
2016-09-02
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

Weaknesses

CWE-693

Affected products

VendorProductAffected versions
pythonpython3.5.0
pythonpython3.5.1
pythonpython3.0
pythonpython3.0.1
pythonpython3.1.0
pythonpython3.1.1
pythonpython3.1.2
pythonpython3.1.3
pythonpython3.1.4
pythonpython3.1.5
pythonpython3.2.0
pythonpython3.2.1
pythonpython3.2.2
pythonpython3.2.3
pythonpython3.2.4
pythonpython3.2.5
pythonpython3.2.6
pythonpython3.3.0
pythonpython3.3.1
pythonpython3.3.2
pythonpython3.3.3
pythonpython3.3.4
pythonpython3.3.5
pythonpython3.3.6
pythonpython3.4.0
pythonpython3.4.1
pythonpython3.4.2
pythonpython3.4.3
pythonpython3.4.4
pythonpython<= 2.7.11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-0772