CVE-2023-29483

e

ventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

References
Link Resource
https://github.com/eventlet/eventlet/issues/913 Exploit Issue Tracking
https://github.com/eventlet/eventlet/releases/tag/v0.35.2 Release Notes
https://github.com/rthalley/dnspython/issues/1045 Exploit Issue Tracking
https://github.com/rthalley/dnspython/releases/tag/v2.6.0 Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ Mailing List
https://security.netapp.com/advisory/ntap-20240510-0001/ Third Party Advisory
https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 Third Party Advisory
https://www.dnspython.org/ Product
https://github.com/eventlet/eventlet/issues/913 Exploit Issue Tracking
https://github.com/eventlet/eventlet/releases/tag/v0.35.2 Release Notes
https://github.com/rthalley/dnspython/issues/1045 Exploit Issue Tracking
https://github.com/rthalley/dnspython/releases/tag/v2.6.0 Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/
https://lists.fedoraproject.org/archives/list/[email protected]/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/
https://security.netapp.com/advisory/ntap-20240510-0001/ Third Party Advisory
https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 Third Party Advisory
https://www.dnspython.org/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:eventlet:eventlet:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:dnspython:dnspython:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

History

04 Nov 2025, 18:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ -

17 Jun 2025, 20:50

Type Values Removed Values Added
References () https://github.com/eventlet/eventlet/issues/913 - () https://github.com/eventlet/eventlet/issues/913 - Exploit, Issue Tracking
References () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 - () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 - Release Notes
References () https://github.com/rthalley/dnspython/issues/1045 - () https://github.com/rthalley/dnspython/issues/1045 - Exploit, Issue Tracking
References () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 - () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 - Release Notes
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ - Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ - Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ - Mailing List
References () https://security.netapp.com/advisory/ntap-20240510-0001/ - () https://security.netapp.com/advisory/ntap-20240510-0001/ - Third Party Advisory
References () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 - () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 - Third Party Advisory
References () https://www.dnspython.org/ - () https://www.dnspython.org/ - Product
First Time Fedoraproject fedora
Fedoraproject
Netapp hci Compute Node
Eventlet
Dnspython dnspython
Netapp bootstrap Os
Netapp
Dnspython
Eventlet eventlet
CPE cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:a:eventlet:eventlet:*:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:a:dnspython:dnspython:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

21 Nov 2024, 07:57

Type Values Removed Values Added
References () https://github.com/eventlet/eventlet/issues/913 - () https://github.com/eventlet/eventlet/issues/913 -
References () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 - () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 -
References () https://github.com/rthalley/dnspython/issues/1045 - () https://github.com/rthalley/dnspython/issues/1045 -
References () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 - () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ -
References () https://security.netapp.com/advisory/ntap-20240510-0001/ - () https://security.netapp.com/advisory/ntap-20240510-0001/ -
References () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 - () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 -
References () https://www.dnspython.org/ - () https://www.dnspython.org/ -

27 Aug 2024, 19:35

Type Values Removed Values Added
CWE CWE-292
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0

26 Jun 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ -

10 Jun 2024, 17:16

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ -
  • () https://security.netapp.com/advisory/ntap-20240510-0001/ -

03 May 2024, 04:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ -

Information

Published : 2024-04-11 14:15

Updated : 2025-11-04 18:15


NVD link : CVE-2023-29483

Mitre link : CVE-2023-29483

CVE.ORG link : CVE-2023-29483


JSON object : View

CWE
CWE-292

DEPRECATED: Trusting Self-reported DNS Name