CVE-2019-5010: Debian Linux

High severity, CVSS 7.5. EPSS: 20.7% chance of exploitation in the next 30 days.

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Opensuse Leap: version 15.1 only
  • Python Python: from 2.7.0, before 2.7.16 (fixed in 2.7.16); from 3.4.0, before 3.4.10 (fixed in 3.4.10); from 3.5.0, before 3.5.7 (fixed in 3.5.7); from 3.6.0, before 3.6.9 (fixed in 3.6.9); from 3.7.0, before 3.7.3 (fixed in 3.7.3)
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only

Published 2019-10-31. Last modified 2026-10-07.