CVE-2023-29483

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
References
Link Resource
https://github.com/eventlet/eventlet/issues/913 Exploit Issue Tracking
https://github.com/eventlet/eventlet/releases/tag/v0.35.2 Release Notes
https://github.com/rthalley/dnspython/issues/1045 Exploit Issue Tracking
https://github.com/rthalley/dnspython/releases/tag/v2.6.0 Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ Mailing List
https://security.netapp.com/advisory/ntap-20240510-0001/ Third Party Advisory
https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 Third Party Advisory
https://www.dnspython.org/ Product
https://github.com/eventlet/eventlet/issues/913 Exploit Issue Tracking
https://github.com/eventlet/eventlet/releases/tag/v0.35.2 Release Notes
https://github.com/rthalley/dnspython/issues/1045 Exploit Issue Tracking
https://github.com/rthalley/dnspython/releases/tag/v2.6.0 Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ Mailing List
https://security.netapp.com/advisory/ntap-20240510-0001/ Third Party Advisory
https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 Third Party Advisory
https://www.dnspython.org/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:eventlet:eventlet:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:dnspython:dnspython:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

History

17 Jun 2025, 20:50

Type Values Removed Values Added
First Time Fedoraproject
Netapp
Netapp hci Compute Node
Eventlet
Eventlet eventlet
Dnspython
Dnspython dnspython
Fedoraproject fedora
Netapp bootstrap Os
References () https://github.com/eventlet/eventlet/issues/913 - () https://github.com/eventlet/eventlet/issues/913 - Exploit, Issue Tracking
References () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 - () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 - Release Notes
References () https://github.com/rthalley/dnspython/issues/1045 - () https://github.com/rthalley/dnspython/issues/1045 - Exploit, Issue Tracking
References () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 - () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 - Release Notes
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ - Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ - Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ - Mailing List
References () https://security.netapp.com/advisory/ntap-20240510-0001/ - () https://security.netapp.com/advisory/ntap-20240510-0001/ - Third Party Advisory
References () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 - () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 - Third Party Advisory
References () https://www.dnspython.org/ - () https://www.dnspython.org/ - Product
CPE cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
cpe:2.3:a:eventlet:eventlet:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:a:dnspython:dnspython:*:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

21 Nov 2024, 07:57

Type Values Removed Values Added
References () https://github.com/eventlet/eventlet/issues/913 - () https://github.com/eventlet/eventlet/issues/913 -
References () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 - () https://github.com/eventlet/eventlet/releases/tag/v0.35.2 -
References () https://github.com/rthalley/dnspython/issues/1045 - () https://github.com/rthalley/dnspython/issues/1045 -
References () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 - () https://github.com/rthalley/dnspython/releases/tag/v2.6.0 -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ -
References () https://security.netapp.com/advisory/ntap-20240510-0001/ - () https://security.netapp.com/advisory/ntap-20240510-0001/ -
References () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 - () https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 -
References () https://www.dnspython.org/ - () https://www.dnspython.org/ -

27 Aug 2024, 19:35

Type Values Removed Values Added
CWE CWE-292
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0

26 Jun 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF/ -

10 Jun 2024, 17:16

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6/ -
  • () https://security.netapp.com/advisory/ntap-20240510-0001/ -

03 May 2024, 04:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH/ -

11 Apr 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-11 14:15

Updated : 2025-06-17 20:50


NVD link : CVE-2023-29483

Mitre link : CVE-2023-29483

CVE.ORG link : CVE-2023-29483


JSON object : View

Products Affected

netapp

  • bootstrap_os
  • hci_compute_node

dnspython

  • dnspython

eventlet

  • eventlet

fedoraproject

  • fedora
CWE
CWE-292

DEPRECATED: Trusting Self-reported DNS Name