Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-3495


Race condition in ZEO/StorageServer.py in Zope Object Database (ZODB) before 3.10.0 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.


Published

2010-10-19T20:00:04.377

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zope zodb ≤ 3.9.7 Yes
Application zope zodb 2.8.11 Yes
Application zope zodb 2.9.11 Yes
Application zope zodb 2.10.9 Yes
Application zope zodb 2.11.4 Yes
Application zope zodb 3.1 Yes
Application zope zodb 3.1.1 Yes
Application zope zodb 3.2 Yes
Application zope zodb 3.2.4 Yes
Application zope zodb 3.3 Yes
Application zope zodb 3.3.3 Yes
Application zope zodb 3.4 Yes
Application zope zodb 3.4.1 Yes
Application zope zodb 3.5 Yes
Application zope zodb 3.6 Yes
Application zope zodb 3.7 Yes
Application zope zodb 3.8 Yes
Application zope zodb 3.8.0 Yes
Application zope zodb 3.8.1 Yes
Application zope zodb 3.8.2 Yes
Application zope zodb 3.8.6 Yes
Application zope zodb 3.9.0 Yes
Application zope zodb 3.9.0b1 Yes
Application zope zodb 3.9.0b2 Yes
Application zope zodb 3.9.0b3 Yes
Application zope zodb 3.9.0b4 Yes
Application zope zodb 3.9.0b5 Yes
Application zope zodb 3.9.0c1 Yes

References