<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 05:43:09 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:3275 — Moderate: python-dns security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:3275</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-dns&lt;/p&gt;
&lt;p&gt;The python-dns package contains the dnslib module that implements a DNS client and additional modules that define certain symbolic constants used by DNS, such as dnstype, dnsclass and dnsopcode.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dnspython: denial of service in stub resolver (CVE-2023-29483)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-dns&lt;/p&gt;
&lt;p&gt;The python-dns package contains the dnslib module that implements a DNS client and additional modules that define certain symbolic constants used by DNS, such as dnstype, dnsclass and dnsopcode.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dnspython: denial of service in stub resolver (CVE-2023-29483)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:3275</guid>
    </item>
    <item>
      <title>bdu:2025-03301</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03301</link>
      <description>bdu:2025-03301</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03301</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2023-29483 — Potential DoS via the Tudoor mechanism in eventlet and dnspython</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2023-29483</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2023-29483</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0385 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</link>
      <description>certfr-2024-avi-0385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</guid>
    </item>
    <item>
      <title>EUVD-2026-258973</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258973</link>
      <description>EUVD-2026-258973</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258973</guid>
    </item>
    <item>
      <title>fkie_cve-2023-29483</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-29483</link>
      <description>&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-29483</guid>
    </item>
    <item>
      <title>GHSA-3rq5-2g8h-59hc — Potential DoS via the Tudoor mechanism in eventlet and dnspython</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3rq5-2g8h-59hc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: eventlet, PyPI: dnspython&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: eventlet, PyPI: dnspython&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3rq5-2g8h-59hc</guid>
    </item>
    <item>
      <title>gsd-2023-29483</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-29483</link>
      <description>gsd-2023-29483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-29483</guid>
    </item>
    <item>
      <title>OESA-2025-1138 — python-dns security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1138</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: python-dns&lt;/p&gt;
&lt;p&gt;\&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;amp;quot;TuDoor&amp;amp;quot; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.(CVE-2023-29483)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: python-dns&lt;/p&gt;
&lt;p&gt;\&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;amp;quot;TuDoor&amp;amp;quot; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.(CVE-2023-29483)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1138</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14047-1 — python310-eventlet-0.36.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14047-1</link>
      <description>&lt;p&gt;python310-eventlet-0.36.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-eventlet-0.36.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14047-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1307 — Potential DoS via the Tudoor mechanism in eventlet and dnspython</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1307</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: dnspython&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: dnspython&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1307</guid>
    </item>
    <item>
      <title>RHSA-2024:0045 — Red Hat Security Advisory: OpenShift Container Platform 4.16.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0045</link>
      <description>&lt;p&gt;dnspython: denial of service in stub resolver golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm containers/image: digest type does not guarantee valid type golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm golang: net/mail: comments in display names are incorrectly handled golang: html/template: errors returned from MarshalJSON methods may break template escaping golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jose: resource exhaustion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dnspython: denial of service in stub resolver golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm containers/image: digest type does not guarantee valid type golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm golang: net/mail: comments in display names are incorrectly handled golang: html/template: errors returned from MarshalJSON methods may break template escaping golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jose: resource exhaustion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0045</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2605-1 — Security update for python-dnspython</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2605-1</link>
      <description>&lt;p&gt;Security update for python-dnspython&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-dnspython&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2605-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-29483</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-29483</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: dnspython, Ubuntu:16.04:LTS: dnspython, Ubuntu:18.04:LTS: dnspython, Ubuntu:20.04:LTS: dnspython, Ubuntu:22.04:LTS: dnspython&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: dnspython, Ubuntu:16.04:LTS: dnspython, Ubuntu:18.04:LTS: dnspython, Ubuntu:20.04:LTS: dnspython, Ubuntu:22.04:LTS: dnspython&lt;/p&gt;
&lt;p&gt;eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;#34;TuDoor&amp;#34; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-29483</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1213 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1213</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Komponenten von Red Hat Enterprise Linux ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Komponenten von Red Hat Enterprise Linux ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1213</guid>
    </item>
  </channel>
</rss>
