{"id":"CVE-2016-0772","details":"The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a \"StartTLS stripping attack.\"","aliases":["PSF-2016-3"],"modified":"2026-04-10T03:46:03.326447Z","published":"2016-09-02T14:59:00.127Z","related":["MGASA-2016-0230","SUSE-SU-2016:2106-1","SUSE-SU-2016:2270-1","SUSE-SU-2016:2653-1","SUSE-SU-2016:2859-1","SUSE-SU-2019:0223-1","SUSE-SU-2020:0114-1","SUSE-SU-2020:0234-1","openSUSE-SU-2020:0086-1","openSUSE-SU-2024:10193-1","openSUSE-SU-2024:10450-1","openSUSE-SU-2024:10536-1","openSUSE-SU-2024:11284-1"],"references":[{"type":"WEB","url":"http://www.splunk.com/view/SP-CAAAPSV"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/02/msg00011.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/91225"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html"},{"type":"WEB","url":"http://www.splunk.com/view/SP-CAAAPUE"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1630.html"},{"type":"ADVISORY","url":"https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-5"},{"type":"ADVISORY","url":"https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-2"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1627.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201701-18"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1629.html"},{"type":"ADVISORY","url":"https://hg.python.org/cpython/raw-file/v2.7.12/Misc/NEWS"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1626.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1628.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1303647"},{"type":"FIX","url":"https://hg.python.org/cpython/rev/b3ce713fb9be"},{"type":"FIX","url":"https://hg.python.org/cpython/rev/d590114c2394"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/06/14/9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/python/cpython","events":[{"introduced":"0"},{"last_affected":"2e789a1f1d84b343a996e8654590703b5fbdd441"},{"introduced":"0"},{"last_affected":"ffccaa40fa237f4afc9eec87c78a98356f9f6e77"},{"introduced":"0"},{"last_affected":"6046c5e0298c25515ea58abc8ab87f7413e3f743"},{"introduced":"0"},{"last_affected":"c1e689ec9677f3222790aaf7da5c8c7361e50115"},{"introduced":"0"},{"last_affected":"5c5f3de16e42d8e9d3f11c9d0e8184659def5ae3"},{"introduced":"0"},{"last_affected":"aa36b9cc0143e8726d387aee8b7918b35e840178"},{"introduced":"0"},{"last_affected":"5757429130b8bba026e75d358ef0494a6ac0aed8"},{"introduced":"0"},{"last_affected":"d858df20d0d82eeefbdbe9982cfd68207a0cd446"},{"introduced":"0"},{"last_affected":"c37a4fdf5472b9460cc38885342ef59bce05753f"},{"introduced":"0"},{"last_affected":"65b2eb9dfebe873e8ee5821f13d5a8c07d9c89c2"},{"introduced":"0"},{"last_affected":"09a7df8301bef5a5ac957371ae9e19c68acdca0a"},{"introduced":"0"},{"last_affected":"27a28589c5ab8603240b63122f48a91b1c6b4ccf"},{"introduced":"0"},{"last_affected":"4fbc0d8baa2126db4ace0c8a03c1773f01abdda6"},{"introduced":"0"},{"last_affected":"bfe36ec1f580248d5e718667c204974275f8974a"},{"introduced":"0"},{"last_affected":"439d88542ef77d5c867b8298e4c2c6be4a412a5e"},{"introduced":"0"},{"last_affected":"e054f452bd9118def58c18aa295662c9845e1c89"},{"introduced":"0"},{"last_affected":"9aa23c5671218dfe62e35945d0ff884f2727d312"},{"introduced":"0"},{"last_affected":"84fc4ba67eedd249ae7643930eacd0058303b95c"},{"introduced":"0"},{"last_affected":"9e2043a5613a6423b7051b08a916b01969c179ed"},{"introduced":"0"},{"last_affected":"a7bf78d3eb3523572f7f306f0108e2c1b81e6a93"},{"introduced":"0"},{"last_affected":"fbd7518a412b162a0b749f6df71b3105140ab253"},{"introduced":"0"},{"last_affected":"18e897250a073e22ebc5e50d59551e44d98f8338"},{"introduced":"0"},{"last_affected":"3101b7076270756f8be699358c69c5d15ea2cc48"},{"introduced":"0"},{"last_affected":"5c26a8afbb6fa43a35e8a1d6942157209890437a"},{"introduced":"0"},{"last_affected":"dbb126103e1c4f2818e0dfc7aa4a689d86565e7a"},{"introduced":"0"},{"last_affected":"f5caf2b30bfe70e5107f816c9e7f7fe3ef5299d9"},{"introduced":"0"},{"last_affected":"fa7193286099f8e4164f4a795afd5ad4a8e229df"},{"introduced":"0"},{"last_affected":"11fc030b6f9294030f0baa15f3bd4e2293e260e4"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"3.5.0"},{"introduced":"0"},{"last_affected":"3.5.1"},{"introduced":"0"},{"last_affected":"3.0"},{"introduced":"0"},{"last_affected":"3.0.1"},{"introduced":"0"},{"last_affected":"3.1.1"},{"introduced":"0"},{"last_affected":"3.1.2"},{"introduced":"0"},{"last_affected":"3.1.3"},{"introduced":"0"},{"last_affected":"3.1.4"},{"introduced":"0"},{"last_affected":"3.1.5"},{"introduced":"0"},{"last_affected":"3.2.1"},{"introduced":"0"},{"last_affected":"3.2.2"},{"introduced":"0"},{"last_affected":"3.2.3"},{"introduced":"0"},{"last_affected":"3.2.4"},{"introduced":"0"},{"last_affected":"3.2.5"},{"introduced":"0"},{"last_affected":"3.2.6"},{"introduced":"0"},{"last_affected":"3.3.0"},{"introduced":"0"},{"last_affected":"3.3.1"},{"introduced":"0"},{"last_affected":"3.3.2"},{"introduced":"0"},{"last_affected":"3.3.3"},{"introduced":"0"},{"last_affected":"3.3.4"},{"introduced":"0"},{"last_affected":"3.3.5"},{"introduced":"0"},{"last_affected":"3.3.6"},{"introduced":"0"},{"last_affected":"3.4.0"},{"introduced":"0"},{"last_affected":"3.4.1"},{"introduced":"0"},{"last_affected":"3.4.2"},{"introduced":"0"},{"last_affected":"3.4.3"},{"introduced":"0"},{"last_affected":"3.4.4"},{"introduced":"0"},{"last_affected":"2.7.11"}]}}],"versions":["v0.9.8","v0.9.9","v1.0.1","v1.0.2","v1.1","v1.1.1","v1.2","v1.2b1","v1.2b2","v1.2b3","v1.2b4","v1.3","v1.3b1","v1.4","v1.4b1","v1.4b2","v1.4b3","v1.5","v1.5.1","v1.5.2","v1.5.2a1","v1.5.2a2","v1.5.2b1","v1.5.2b2","v1.5.2c1","v1.5a1","v1.5a2","v1.5a3","v1.5a4","v1.5b1","v1.5b2","v1.6a1","v1.6a2","v2.0","v2.0b1","v2.0b2","v2.0c1","v2.1","v2.1a1","v2.1a2","v2.1b1","v2.1b2","v2.1c1","v2.1c2","v2.2a3","v2.3c1","v2.3c2","v2.4","v2.4a1","v2.4a2","v2.4a3","v2.4b1","v2.4b2","v2.4c1","v2.5a0","v2.5a1","v2.5a2","v2.5b1","v2.5b2","v2.5b3","v2.6","v2.6a1","v2.6a2","v2.6a3","v2.6b1","v2.6b2","v2.6b3","v2.6rc1","v2.6rc2","v2.7","v2.7.1","v2.7.10rc1","v2.7.11","v2.7.11rc1","v2.7.1rc1","v2.7.2rc1","v2.7.3rc1","v2.7.4rc1","v2.7.5","v2.7.6rc1","v2.7.8","v2.7.9rc1","v2.7a1","v2.7a2","v2.7a3","v2.7a4","v2.7b1","v2.7b2","v2.7rc1","v2.7rc2","v3.0","v3.0a1","v3.0a2","v3.0a3","v3.0a4","v3.0a5","v3.0b1","v3.0b2","v3.0b3","v3.0rc1","v3.0rc2","v3.0rc3","v3.1","v3.1.1","v3.1.1rc1","v3.1.2","v3.1.2rc1","v3.1.3","v3.1.3rc1","v3.1.4","v3.1.4rc1","v3.1.5","v3.1.5rc1","v3.1.5rc2","v3.1a1","v3.1a2","v3.1b1","v3.1rc1","v3.1rc2","v3.2","v3.2.4","v3.2.4rc1","v3.2.5","v3.2.6","v3.2.6rc1","v3.2a1","v3.2a2","v3.2a3","v3.2a4","v3.2b1","v3.2b2","v3.2rc1","v3.2rc2","v3.2rc3","v3.3.0","v3.3.0a2","v3.3.0a3","v3.3.0a4","v3.3.0b1","v3.3.0b2","v3.3.0rc1","v3.3.0rc2","v3.3.0rc3","v3.3.1","v3.3.1rc1","v3.3.2","v3.3.3","v3.3.3rc1","v3.3.3rc2","v3.3.4","v3.3.4rc1","v3.3.5","v3.3.5rc2","v3.3.6","v3.3.6rc1","v3.4.0","v3.4.0a1","v3.4.0a2","v3.4.0a3","v3.4.0a4","v3.4.0b1","v3.4.0b2","v3.4.0b3","v3.4.0rc1","v3.4.0rc2","v3.4.0rc3","v3.4.1","v3.4.1rc1","v3.4.2","v3.4.2rc1","v3.4.3","v3.4.3rc1","v3.4.4","v3.4.4rc1","v3.5.0","v3.5.0a1","v3.5.0a2","v3.5.0a3","v3.5.0a4","v3.5.0b1","v3.5.0b3","v3.5.0b4","v3.5.0rc1","v3.5.0rc2","v3.5.0rc3","v3.5.0rc4","v3.5.1","v3.5.1rc1"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"3.1.0"}]},{"events":[{"introduced":"0"},{"last_affected":"3.2.0"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0772.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"}]}