Python Other Vulnerability - CVE-2014-9365 - Vulnerability Database

Python Other Vulnerability - CVE-2014-9365

Medium
Reference: CVE-2014-9365
Title: Python Other Vulnerability
Overview:

The HTTP clients in the (1) httplib (2) urllib (3) urllib2 and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3 when accessing an HTTPS URL do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject39s (b) Common Name or (c) subjectAltName field of the X.509 certificate which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.