GHSA-j6m4-frxh-p4x8

Suggest an improvement
Source
https://github.com/advisories/GHSA-j6m4-frxh-p4x8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j6m4-frxh-p4x8/GHSA-j6m4-frxh-p4x8.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-j6m4-frxh-p4x8
Aliases
Published
2022-05-17T05:44:11Z
Modified
2024-11-30T05:42:01.199276Z
Summary
Zope Object Database Denial of Service vulnerability
Details

Race condition in ZEO/StorageServer.py in Zope Object Database (ZODB) before 3.10.0a2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.

Database specific
{
    "nvd_published_at": "2010-10-19T20:00:00Z",
    "cwe_ids": [
        "CWE-362"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-01T16:29:16Z"
}
References

Affected packages

PyPI / zodb3

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.0a2

Affected versions

3.*

3.1.5
3.2.10
3.3.1
3.4.2
3.5.0
3.5.1
3.6.0
3.7.0
3.7.2
3.8.0a1
3.8.0b1
3.8.0b2
3.8.0b3
3.8.0b4
3.8.0c1
3.8.0
3.8.1b1
3.8.1b2
3.8.1b3
3.8.1b4
3.8.1b5
3.8.1b6
3.8.1b7
3.8.1b8
3.8.1b9
3.8.1
3.8.2
3.8.3b1
3.8.3
3.8.4
3.8.5
3.8.6
3.9.0a1
3.9.0a2
3.9.0a3
3.9.0a4
3.9.0a5
3.9.0a6
3.9.0a7
3.9.0a9
3.9.0a10
3.9.0a11
3.9.0a12
3.9.0b1
3.9.0b2
3.9.0b3
3.9.0b4
3.9.0b5
3.9.0c1
3.9.0c2
3.9.0c3
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.5
3.9.6
3.9.7
3.10.0a1