VDB
RHSA-2024:3483
RHSA-2024:3483
PUBLISHED
CVSS 5.900000095367432 MEDIUM
The dnspython stub resolver is vulnerable to a denial of service (DoS) risk if an attacker sends a malicious response forged with the correct address and port before a legitimate one arrives on the UDP port used by dnspython for the query. In such cases, dnspython could either switch to another resolver or abandon the query altogether, potentially leading to service denial for that resolution.
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | ansible-automation-platform-24/hub-rhel8@sha256:8c0291925a0b08c63132702d8aee6a35cede417d9e642bf30a343d65f6f5cf62_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/eda-controller-ui-rhel8@sha256:0f4daadbe11b8e6712abaf693f68c05d2f1049e3e08f191f8b4cbda7a8764388_arm64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/de-minimal-rhel8@sha256:1095c9cce31b485eb2c3e8fb50f7d88536e269a51ede8424b933d68b403f98ba_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/ansible-builder-rhel9@sha256:1fd01a25b38fd46722a69b8fda118ff1b39374f0d3ac09523b6e0cfc3dd1d28f_ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9 | * |
| Red Hat | ansible-automation-platform-24/aap-cloud-billing-rhel8-operator@sha256:c7cd14d35a72298e67ef82e5b9110356c4b8d37eef0619ed345bac17ef471113_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/eda-controller-ui-rhel8@sha256:f5e7f5162085fac689cb7c767b535e940b126ac3d0e43a670e3acfb612f6c412_ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/ee-supported-rhel8@sha256:adc0fc0080e38095ebfd37797f12ee3247f5a25ad1a41854bcd38271fc38a5b2_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/aap-must-gather-rhel8@sha256:324d0755750111638f536d51f77cd1e53537171da1e0988e63e06594aec61b00_s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/ansible-python-base-rhel8@sha256:f0270b5d73d7ace40cd115512533a29e23fbadbf2c0467495f669e9825293a2e_ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform/platform-operator-bundle@sha256:9f0293a548ae1b0d55512d5485b0daf136885f864915fe8418b54d979bbae8fd_ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/hub-rhel8-operator@sha256:7c7b81dc109ed58af134e6c1015b936dab076188d546f25b21f87b29b6513cba_arm64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/ee-minimal-rhel8@sha256:c8531cccfc8ee667dee0e379fd4e247e47be65ed01743ecf98bde6d596b3f2ae_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/de-minimal-rhel9@sha256:bc0d79e2cb0e45a673c65d668f4cbf16c3e8b848d8c00d317c57134ab0afab07_s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9 | * |
| Red Hat | ansible-automation-platform-24/ee-minimal-rhel9@sha256:a0eda585ed97264382de28ca4e984020a24a94aa1abdc15023b75b37e76ccdda_arm64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9 | * |
| Red Hat | ansible-automation-platform-24/platform-resource-runner-rhel8@sha256:c1f56670d4ebec1795f9d3380e3fe7c047317ac77b83e6f7fee1c01a111fa3b6_s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/platform-resource-runner-rhel8@sha256:dc5dffa9fcc135bfe0da4e965e488ce00258b94ebeeac17c65677bec34ec10fd_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/hub-web-rhel8@sha256:a7d0260ee8599da21887386acb8386460b35b603364a87ed70c16336b22e8165_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/controller-rhel8-operator@sha256:90615242dad4750f9962b1224bbfd3b5bf21dba0af343ac66454cf52575de2ec_ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/controller-rhel8@sha256:5658fec249664cd3a22f4055e489e9b6d368d52167d44dd628a65ded8f2b779a_amd64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
| Red Hat | ansible-automation-platform-24/hub-rhel8-operator@sha256:9705161190de704d4e1bf5af7179b097633ec188870355244f4c9d469dfaacc7_ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8 | * |
…and 96 more
Timeline
- May 30, 2024 CVE Published
- Aug 4, 2026 CVE Updated
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Security Advisory
- Aug 4, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:3483 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2274520 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3483.json advisory
- https://access.redhat.com/security/cve/CVE-2023-29483 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-29483 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-29483 advisory
- https://www.dnspython.org/news/2.6.0rc1/ advisory