CVE-2023-29483

medium
Published 2024-04-11 Β· Modified 2024-11-18
CVSS v3
β€”
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: python-dns security update

Predictions

Exploit likelihood
30%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description dnspython: denial of service in stub resolver Red Hat statement The vulnerability in dnspython where it may accept a malicious DNS response over a legitimate one due to timing issues poses a moderate severity risk. While the impact is limited to potential denial of service for DNS resolution requests, it requires precise timing and the ability to send malicious responses before…

Description

dnspython: denial of service in stub resolver

Red Hat statement

The vulnerability in dnspython where it may accept a malicious DNS response over a legitimate one due to timing issues poses a moderate severity risk. While the impact is limited to potential denial of service for DNS resolution requests, it requires precise timing and the ability to send malicious responses before legitimate ones arrive. This attack vector relies on the attacker's ability to predict or manipulate the timing of DNS responses, making it more complex to exploit compared to other vulnerabilities. However, if successfully exploited, it can disrupt DNS resolution services, affecting the availability of the targeted domain or service.

CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Ansible Automation Platform 2.4 for RHEL 8ansible-automation-platform-24/ee-supported-rhel8:1.0.0-661RHSA-2024:34832024-05-30T00:00:00Z
Red Hat Ansible Automation Platform 2.4 for RHEL 9ansible-automation-platform-24/ee-supported-rhel9:1.0.0-660RHSA-2024:34832024-05-30T00:00:00Z
Red Hat Enterprise Linux 8python-dns-0:1.15.0-12.el8_10RHSA-2024:32752024-05-22T00:00:00Z
Red Hat Enterprise Linux 9python-dns-0:2.6.1-3.el9RHSA-2024:94232024-11-12T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-ironic-rhel9:v4.13.0-202407230838.p0.g0456ffe.assembly.stream.el9RHSA-2024:48462024-07-31T00:00:00Z
Red Hat OpenShift Container Platform 4.14openshift4/ose-ironic-rhel9:v4.14.0-202407301840.p0.g2d4e89c.assembly.stream.el9RHSA-2024:49602024-08-07T00:00:00Z
Red Hat OpenShift Container Platform 4.15openshift4/ose-ironic-rhel9:v4.15.0-202407181606.p0.gea6d005.assembly.stream.el9RHSA-2024:46992024-07-25T00:00:00Z
Red Hat OpenShift Container Platform 4.16python-eventlet-0:0.33.1-6.el9RHSA-2024:00452024-06-27T00:00:00Z

Package state

ProductPackageState
Red Hat Ansible Automation Platform 2aap-cloud-metrics-collector-containerAffected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-dellemc-openmanage-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-builder-rhel8Not affected
Red Hat Enterprise Linux 10python-dnsNot affected
Red Hat Enterprise Linux 7python-dnsOut of support scope
Red Hat Enterprise Linux 8python27:2.7/python-dnsWill not fix
Red Hat OpenStack Platform 17.1python-eventletWill not fix

Apply commands

bash fix
Apply RHSA-2024:3483 for Red Hat Ansible Automation Platform 2.4 for RHEL 8
yum update -y ansible-automation-platform
# or:
dnf upgrade -y ansible-automation-platform

Affected

VendorProductVersion
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Enterprise Linux 10Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 2.6.0-1
sid Fixed 2.6.0-1
forky Fixed 2.6.0-1
bullseye Affected β€”
bookworm Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed python3-dns-2.6.1-3.el9.noarch.rpm
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Package impact

EcosystemPackageVulnerableFixed
python PyPIdnspython<2.6.12.6.1
python PyPIeventlet<0.35.20.35.2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.