Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-84278.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-84278
Upstream
Published
2014-12-12T11:59:07Z
Modified
2026-09-08T05:27:25Z
Summary
CVE-2014-9365 affecting package docbook5-style-xsl 1.79.2-11
Details

The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

References

Affected packages

Azure Linux:3 / docbook5-style-xsl

Package

Name
docbook5-style-xsl
Purl
pkg:rpm/azure-linux/docbook5-style-xsl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.79.2-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-84278.json"