CVE-2023-29483

HIGH

eventlet < 0.35.2 - DNS Spoofing via Self-reported DNS Name Trust

Title source: llm
STIX 2.1

Description

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

Scores

CVSS v3 7.0
EPSS 0.0860
EPSS Percentile 92.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-292
Status published
Products (8)
dnspython/dnspython < 2.6.0
eventlet/eventlet < 0.35.2
fedoraproject/fedora 38
fedoraproject/fedora 39
fedoraproject/fedora 40
netapp/bootstrap_os
pypi/dnspython 0 - 2.6.1PyPI
pypi/eventlet 0 - 0.35.2PyPI
Published Apr 11, 2024
Tracked Since Feb 18, 2026