CVE-2023-29483
HIGHDescription
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
Is your site exposed to CVE-2023-29483?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
7.0
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Weakness Type (CWE)
CWE-292
CWE-292
Affected Products
| Vendor | Product |
|---|---|
| eventlet | eventlet |
| dnspython | dnspython |
| fedoraproject | fedora |
| fedoraproject | fedora |
| fedoraproject | fedora |
| netapp | bootstrap_os |
| netapp | hci_compute_node |
References
Exploits
Other References
https://github.com/eventlet/eventlet/releases/tag/v0.35.2
https://github.com/rthalley/dnspython/releases/tag/v2.6.0
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/
https://security.netapp.com/advisory/ntap-20240510-0001/
https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713
https://www.dnspython.org/
https://github.com/eventlet/eventlet/releases/tag/v0.35.2
https://github.com/rthalley/dnspython/releases/tag/v2.6.0
Frequently Asked Questions
What is CVE-2023-29483? +
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. It has a CVSS v3.1 base score of 7.0 (HIGH).
How severe is CVE-2023-29483? +
CVE-2023-29483 has a CVSS v3.1 score of 7.0 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2023-29483? +
CVE-2023-29483 affects products from dnspython, eventlet, fedoraproject, netapp, specifically: bootstrap_os, dnspython, eventlet, fedora, hci_compute_node. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-29483? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.